s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.wolfsbane

📛 Threat Title

Malware family: WolfsBane

Category: WolfsBane First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.wolfsbane`. Printable name: WolfsBane.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.wolfsbane VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.wolfsbane

IOC database

Type
domain
Value
elf.wolfsbane
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.wolfsbane

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.wolfsbane

References (1)

Remediations (10)

  • web:assets.adgm.com

    Key Insights 1. from the Analysis: WolfsBane Linux Windows Version of Backdoor: as backdoor Gelsevirine: mechanism, Gelsemium. WolfsBane closely associated Gelsevirine Gelsemium similarities previously analogous confidence, configuration communication, structures. on consistent a similar WolfsBane command with shared patterns and is attributed execution launcher, and Persistence and backdoor ...

  • web:bazaar.abuse.ch

    Malware samples associated with tag WolfsBane MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with WolfsBane . Database Entry

  • web:blogs.npav.net

    The discovery of WolfsBane and FireWood highlights a concerning shift by advanced threat actors towards targeting Linux platforms. With Linux's widespread use in servers and critical systems, these malware families pose significant risks to enterprises worldwide.

  • web:candid.technology

    A China-based advanced persistent threat (APT) group, Gelsemium, has been linked to two Linux malware families — WolfsBane and FireWood — capable of stealing sensitive data, maintaining stealthy access, and executing remote commands. This marks the first known instance of the group employing ...

  • web:cybersecsentinel.com

    Overview The WolfsBane malware , attributed to the Gelsemium APT group, is a newly identified Linux backdoor designed for cyberespionage. First analyzed by ESET, WolfsBane is a counterpart to the Windows-based Gelsevirine malware . The Gelsemium APT group, active since 2014, has historically targeted critical infrastructure, with a particular focus on East and Southeast Asia. Award-winning news ...

  • web:dailysecurityreview.com

    Chinese hackers are targeting Linux systems with the new WolfsBane malware , raising concerns about a potential widespread data breach. Learn about this sophisticated threat and its implications.

  • web:hivepro.com

    Attack Details #1 Two sophisticated Linux backdoors are dicovered, WolfsBane and FireWood, both intricately tied to the Gelsemium APT group, a known player in cyberespionage. WolfsBane , a Linux variant of the Gelsevirine backdoor, and FireWood, an extension of the Project Wood backdoor. This shift towards Linux-focused malware signals a strategic pivot by threat actors, likely driven by ...

  • web:threats.wiz.io

    The malware samples were likely discovered during incident responses in East Asia, with archives uploaded to VirusTotal from Taiwan, the Philippines, and Singapore. WolfsBane's execution chain involves a dropper, launcher, and backdoor, while FireWood integrates kernel modules for process hiding and uses TEA-encrypted C&C communications.

  • web:www.bleepingcomputer.com

    The latest news about WolfsBane Chinese hackers target Linux with new WolfsBane malware A new Linux backdoor called 'WolfsBane' has been discovered, believed to be a port of Windows malware used ...

  • web:www.enigmasoftware.com

    WolfsBane : A Linux Adaptation of Gelsevirine WolfsBane is believed to be the Linux variant of Gelsevirine, a backdoor that has been employed on Windows systems since 2014. Alongside WolfsBane , researchers have identified another previously undocumented implant, FireWood, which is tied to a separate malware suite named Project Wood.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.