Gelsemium

Description

(ESET) The Gelsemium group has been active since at least 2014 and was described in the past by a few security companies .Gelsemium’s name comes from one possible translation we found while reading a report from VenusTech who dubbed the group 狼毒草 for the first time .It’s the name of a genus of flowering plants belonging to the family Gelsemiaceae, Gelsemium elegans is the species that contains toxic compounds like Gelsemine, Gelsenicine and Gelsevirine, which we chose as names for the three components of this malware family.

Names

NameName-Giver
GelsemiumESET

Country

Motivation

  • Information theft and espionage

First Seen

2014

Observed Sectors

Observed Countries

Tools

Operations

Information

Other Information

Uuid

80d60b05-bf0a-4630-afa8-666fa6f72147

Last Card Change

2024-12-26