Gelsemium is a cyberespionage APT group active since at least 2014. Public reporting in the provided content describes victims in East Asia and the Middle East, including governments, religious organizations, electronics manufacturers, and universities. Unit 42 also reported activity attributed with moderate confidence to Gelsemium targeting a Southeast Asian government, including vulnerable IIS servers and long-term access operations. The group has not been formally attributed to any specific state in the cited Unit 42 reporting, although other cited reporting in the content describes it as China-aligned or tied to Chinese interests. ESET attributed multiple campaigns to Gelsemium and linked the group to the BigNox/NoxPlayer supply-chain attack previously reported as Operation NightScout. ESET described a modular malware framework including Gelsemine, Gelsenicine, and Gelsevirine. Gelsemine is a C++ first-stage dropper with embedded compressed stages; Gelsenicine is a loader; and Gelsevirine is the final stage backdoor. Related tooling and malware mentioned in the content include OwlProxy, SessionManager, Chrommme, and FireWood. Reporting in the content also notes code overlap between OwlProxy and Gelsevirine, and victimology overlap plus the rare SessionManager and OwlProxy combination were used by researchers to associate some IIS-focused activity with Gelsemium. Observed tradecraft in the provided content includes use of HTTP/S for command-and-control, custom shellcode to map embedded DLLs into memory, decompression and decryption of DLLs and shellcode, token manipulation to bypass UAC on Windows 7, security software discovery, and anti-analysis through junk code generation. In the Southeast Asian government intrusion cluster CL-STA-0046, tooling included OwlProxy, SessionManager, Cobalt Strike, Meterpreter, Earthworm, Spoolfool, web shells such as reGeorg, China Chopper, and AspxSpy, reconnaissance commands, network discovery, SMB lateral movement, and attempted privilege escalation via Potato Suite and exploitation of CVE-2022-21999. Known aliases and related names directly mentioned in the content include Gelsemium, Gelsemine, Gelsenicine, Gelsevirine, Chrommme, OwlProxy, SessionManager, and FireWood.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
22 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Gelsemium is associated with the deployment of the FireWood backdoor, which uses a kernel driver rootkit module to hide processes and execute attacker commands.
Gelsemium is a Chinese APT group associated with the use of privilege escalation tools such as JuicyPotato/SweetPotato, and has been linked to attacks leveraging SAP NetWeaver vulnerabilities.
Referenced in connection with a Linux backdoor named WolfsBane.
Cyber-espionage activity against Southeast Asian government IIS servers, establishing stealthy footholds via web shells, deploying custom IIS backdoors/proxy tooling (SessionManager, OwlProxy), and using tunneling/C2 frameworks (EarthWorm, Cobalt Strike) plus privilege-escalation tooling to expand access and collect intelligence.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.