Gelsemium

S0666

Malware.View on attack.mitre.org

About this malware

Gelsemium is a modular malware comprised of a dropper (Gelsemine), a loader (Gelsenicine), and main (Gelsevirine) plug-ins written using the Microsoft Foundation Class (MFC) framework. Gelsemium has been used by the Gelsemium group since at least 2014.

Techniques used33

Procedure examples33

TechniqueProcedure example
T1005
Data from Local System

Gelsemium can collect data from a compromised host.

T1008
Fallback Channels

Gelsemium can use multiple domains and protocols in C2.

T1012
Query Registry

Gelsemium can open random files and Registry keys to obscure malware behavior from sandbox analysis.

T1027.011
Fileless Storage

Gelsemium can store its components in the Registry.

T1027.015
Compression

Gelsemium has the ability to compress its components.

T1027.016
Junk Code Insertion

Gelsemium can use junk code to hide functions and evade detection.

T1033
System Owner/User Discovery

Gelsemium has the ability to distinguish between a standard user and an administrator on a compromised host.

T1036.001
Invalid Code Signature

Gelsemium has used unverified signatures on malicious DLLs.

T1036.005
Match Legitimate Resource Name or Location

Gelsemium has named malicious binaries `serv.exe`, `winprint.dll`, and `chrome_elf.dll` and has set its persistence in the Registry with the key value Chrome Update to appear legitimate.

T1055.001
Dynamic-link Library Injection

Gelsemium has the ability to inject DLLs into specific processes.

T1057
Process Discovery

Gelsemium can enumerate running processes.

T1059.003
Windows Command Shell

Gelsemium can use a batch script to delete itself.

T1070.004
File Deletion

Gelsemium can delete its dropper component from the targeted system.

T1070.006
Timestomp

Gelsemium has the ability to perform timestomping of files on targeted systems.

T1071.001
Web Protocols

Gelsemium can use HTTP/S in C2 communications.

View all 33 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. ESET Gelsemium June 2021 Open source
    Dupuy, T. and Faou, M. (2021, June). Gelsemium. Retrieved November 30, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.