ESET Discovers New Linux Malware
WolfsBane is an all-in-one malware that has hit the Linux operating system and includes a dropper, a launcher, and a backdoor.
WolfsBane, a Chinese malware, has been discovered by ESET and is being used by a group known as Gelsemium. This malware is listed as an all-in-one because it contains everything necessary to do what it needs to do, including a dropper (named cron), which “drops” the launcher disguised as a KDE desktop component. WolfsBane then (if needed) disables SELinux, creates required system service files, and/or modifies a configuration for persistence. The malware also includes the Hider rootkit, which is capable of hooking into functions like open, stat, readdir, and access. The reason why this is labeled an all-in-one is because it doesn't depend on the work of others to succeed; everything is included. WolfsBane's key feature is the ability to grant control over a compromised system to those deploying it.
ESET isn't sure how the attackers are deploying WolfsBane, but it does know that Gelsemium (active since 2014) exploited a previously unknown web application vulnerability. As of now, the primary targets of WolfsBane are in East Asia and the Middle East.
This also comes at the same time that a backdoor (named FireWood) has been discovered within a file named usbdev.ko, which is a kernel driver module that works as a rootkit to hide processes. FireWood then uses a configuration file, kdeinit, that is encrypted with a single-byte key and renames its process based on the value within the configuration file.
ESET has said that although they "lack concrete evidence regarding the initial access vector, the presence of multiple webshells…and the tactics, techniques, and procedures (TTPs) used by the Gelsemium APT group in recent years, we conclude with medium confidence that the attackers exploited an unknown web application vulnerability to gain server access."

Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters
Support Our Work
Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.

News
-
System76 Releases COSMIC Alpha 7
With scores of bug fixes and a really cool workspaces feature, COSMIC is looking to soon migrate from alpha to beta.
-
OpenMandriva Lx 6.0 Available for Installation
The latest release of OpenMandriva has arrived with a new kernel, an updated Plasma desktop, and a server edition.
-
TrueNAS 25.04 Arrives with Thousands of Changes
One of the most popular Linux-based NAS solutions has rolled out the latest edition, based on Ubuntu 25.04.
-
Fedora 42 Available with Two New Spins
The latest release from the Fedora Project includes the usual updates, a new kernel, an official KDE Plasma spin, and a new System76 spin.
-
So Long, ArcoLinux
The ArcoLinux distribution is the latest Linux distribution to shut down.
-
What Open Source Pros Look for in a Job Role
Learn what professionals in technical and non-technical roles say is most important when seeking a new position.
-
Asahi Linux Runs into Issues with M4 Support
Due to Apple Silicon changes, the Asahi Linux project is at odds with adding support for the M4 chips.
-
Plasma 6.3.4 Now Available
Although not a major release, Plasma 6.3.4 does fix some bugs and offer a subtle change for the Plasma sidebar.
-
Linux Kernel 6.15 First Release Candidate Now Available
Linux Torvalds has announced that the release candidate for the final release of the Linux 6.15 series is now available.
-
Akamai Will Host kernel.org
The organization dedicated to cloud-based solutions has agreed to host kernel.org to deliver long-term stability for the development team.