WolfsBane

First seen
2020-06-01 00:00:00
Malware type
rat
Family
Malware family
Profile updated
2026-07-07 14:24:54

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:us country_code:ru

Context

WolfsBane is a remote access trojan designed for cyber espionage activities, primarily targeting government and technology sectors in the United States and Russia. It allows attackers to gain unauthorized access and control over infected systems.

Detection coverage

  • 3 YARA rules

Detection rules

  • SEKOIA_Apt_Gelsemium_Wolfsbane_Backdoor (yara-rule)
  • SEKOIA_Apt_Gelsemium_Wolfsbane_Launcher (yara-rule)
  • SEKOIA_Apt_Gelsemium_Wolfsbane_Rootkit (yara-rule)

Reports & references

  • ESET — Unveiling Wolfsbane Gelsemiums Linux Counterpart To Gelsevirine (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Wolfsbane (report)

External references