Gelsemium
MITRE ATT&CK: S0666 View on attack.mitre.org
Aliases: Gelsevirine, Gelsenicine, Gelsemine, Gelsemium
- First seen
- 2014-01-01 00:00:00
- Malware type
- dropper, loader, backdoor
- Family
- Malware family
- Operating systems
- windows
- Last IoC activity
- 2026-06-25 09:55:40
- Profile updated
- 2026-07-07 13:23:11
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:vn country_code:my country_code:th
Context
Gelsemium is a modular malware comprised of a dropper (Gelsemine), a loader (Gelsenicine), and main (Gelsevirine) plug-ins written using the Microsoft Foundation Class (MFC) framework. Gelsemium has been used by the Gelsemium group since at least 2014.
Detection coverage
- 9 YARA rules
- 537 Sigma rules
Malware & tools used
- Dynamic Resolution (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Bypass User Account Control (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Windows Service (attack-pattern)
- File Deletion (attack-pattern)
- Reflective Code Loading (attack-pattern)
- Print Processors (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Virtualization/Sandbox Evasion (attack-pattern)
- Fileless Storage (attack-pattern)
- Modify Registry (attack-pattern)
- Process Discovery (attack-pattern)
- DNS (attack-pattern)
- File and Directory Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- Security Software Discovery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Fallback Channels (attack-pattern)
- Data from Local System (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- Access Token Manipulation (attack-pattern)
- Timestomp (attack-pattern)
- Query Registry (attack-pattern)
Detection rules
- ARKBIRD_SOLG_APT_Gelsemium_Gelsemine_June_2021_1 (yara-rule)
- ARKBIRD_SOLG_APT_Gelsemium_Gelsenicine_June_2021_2 (yara-rule)
- ARKBIRD_SOLG_APT_Gelsemium_Gelsenicine_June_2021_1 (yara-rule)
- ARKBIRD_SOLG_APT_Gelsemium_Gelsevirine_June_2021_1 (yara-rule)
- DITEKSHEN_MALWARE_Win_Gelsemine (yara-rule)
- SEKOIA_Apt_Gelsemium_Firewood_Backdoor (yara-rule)
- SEKOIA_Apt_Gelsemium_Wolfsbane_Backdoor (yara-rule)
- SEKOIA_Apt_Gelsemium_Wolfsbane_Launcher (yara-rule)
- SEKOIA_Apt_Gelsemium_Wolfsbane_Rootkit (yara-rule)
Reports & references
- ESET — Eset Gelsemium (report)
- MITRE ATT&CK — S0666 (report)
External references
- mitre-attack — S0666
- Gelsevirine
- Gelsenicine
- Gelsemine
- ESET Gelsemium June 2021
- misp-galaxy
- misp-galaxy