TF-MAL-elf.wolfsbane
📛 Threat Title
Malware family: WolfsBane
Description
ThreatFox malware family `elf.wolfsbane`. Printable name: WolfsBane.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.wolfsbane
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.wolfsbane
IOC database
- Type
- domain
- Value
elf.wolfsbane- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.wolfsbane
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.wolfsbane
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:assets.adgm.com
Key Insights 1. from the Analysis: WolfsBane Linux Windows Version of Backdoor: as backdoor Gelsevirine: mechanism, Gelsemium. WolfsBane closely associated Gelsevirine Gelsemium similarities previously analogous confidence, configuration communication, structures. on consistent a similar WolfsBane command with shared patterns and is attributed execution launcher, and Persistence and backdoor ...
-
web:bazaar.abuse.ch
Malware samples associated with tag WolfsBane MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with WolfsBane . Database Entry
-
web:blogs.npav.net
The discovery of WolfsBane and FireWood highlights a concerning shift by advanced threat actors towards targeting Linux platforms. With Linux's widespread use in servers and critical systems, these malware families pose significant risks to enterprises worldwide.
-
web:candid.technology
A China-based advanced persistent threat (APT) group, Gelsemium, has been linked to two Linux malware families — WolfsBane and FireWood — capable of stealing sensitive data, maintaining stealthy access, and executing remote commands. This marks the first known instance of the group employing ...
-
web:cybersecsentinel.com
Overview The WolfsBane malware , attributed to the Gelsemium APT group, is a newly identified Linux backdoor designed for cyberespionage. First analyzed by ESET, WolfsBane is a counterpart to the Windows-based Gelsevirine malware . The Gelsemium APT group, active since 2014, has historically targeted critical infrastructure, with a particular focus on East and Southeast Asia. Award-winning news ...
-
web:dailysecurityreview.com
Chinese hackers are targeting Linux systems with the new WolfsBane malware , raising concerns about a potential widespread data breach. Learn about this sophisticated threat and its implications.
-
web:hivepro.com
Attack Details #1 Two sophisticated Linux backdoors are dicovered, WolfsBane and FireWood, both intricately tied to the Gelsemium APT group, a known player in cyberespionage. WolfsBane , a Linux variant of the Gelsevirine backdoor, and FireWood, an extension of the Project Wood backdoor. This shift towards Linux-focused malware signals a strategic pivot by threat actors, likely driven by ...
-
web:threats.wiz.io
The malware samples were likely discovered during incident responses in East Asia, with archives uploaded to VirusTotal from Taiwan, the Philippines, and Singapore. WolfsBane's execution chain involves a dropper, launcher, and backdoor, while FireWood integrates kernel modules for process hiding and uses TEA-encrypted C&C communications.
-
web:www.bleepingcomputer.com
The latest news about WolfsBane Chinese hackers target Linux with new WolfsBane malware A new Linux backdoor called 'WolfsBane' has been discovered, believed to be a port of Windows malware used ...
-
web:www.enigmasoftware.com
WolfsBane : A Linux Adaptation of Gelsevirine WolfsBane is believed to be the Linux variant of Gelsevirine, a backdoor that has been employed on Windows systems since 2014. Alongside WolfsBane , researchers have identified another previously undocumented implant, FireWood, which is tied to a separate malware suite named Project Wood.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.