Gelsemium
Also reported as 狼毒草. Linked to China by one source.
Reports per quarter
Techniques seen in the last two years
- T1014 1 report
- T1027.009 1 report
- T1036.005 1 report
- T1037.004 1 report
- T1041 1 report
- T1056 1 report
- T1059.004 1 report
- T1070.004 1 report
- T1070.006 1 report
- T1070.009 1 report
Show all 22 techniques Show fewer
Counts come from technique IDs in the actor's report text.
CVEs named in reports
- CVE-2012-0158 KEV ransomware
- CVE-2012-5687
- CVE-2013-5947
- CVE-2014-1225
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-4404 KEV
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-1130 KEV
- CVE-2015-1635 KEV
Show all 27 CVEs Show fewer
- CVE-2015-2051 KEV
- CVE-2015-7248
- CVE-2017-11882 KEV ransomware
- CVE-2017-5638 KEV ransomware
- CVE-2018-10562 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2022-21999 KEV ransomware
- CVE-2023-5631 KEV
- CVE-2024-21413 KEV
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The SessionManager IIS backdoor- a possibly overlooked GELSEMIUM artefact
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The SessionManager IIS backdoor- a possibly overlooked GELSEMIUM artefact
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t22021
Show all 14 reports Show fewer
-
Gelsemium- When threat actors go gardening
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Gelsemium- When threat actors go gardening
Newest first. Details opens the report in Explore.