FireWood is a backdoor associated with the China-aligned threat actor Gelsemium. It was first documented by ESET in November 2024, and Intezer later reported a new variant that retains the malware’s core functionality while introducing some implementation and configuration changes. FireWood has been described as using a kernel driver rootkit module named usbdev.ko to hide processes and execute attacker commands. Researchers noted that the kernel module for the newer variant was not collected, so it is currently unclear whether that component was also updated. High-confidence reporting in the provided content links FireWood to Gelsemium, but does not specify infection vectors, targeted industries, or concrete indicators of compromise beyond the usbdev.ko module name.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A new variant of the FireWood ransomware, likely used to encrypt files and demand ransom.
FireWood is a backdoor capable of leveraging a kernel driver rootkit (usbdev.ko) to hide processes and execute attacker-supplied commands. Recent variants show changes in implementation and configuration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.