elf.wellmess
Malware⚠️ Overview
elf.wellmess is a Linux‑native variant of the WellMess remote access trojan (RAT) attributed to the Russian state‑sponsored threat group APT29 (also tracked as Cozy Bear, Nobelium, Midnight Blizzard). First publicly documented by the UK National Cyber Security Centre (NCSC) and CISA in July 2020 during a coordinated campaign targeting COVID‑19 vaccine research organisations in the United Kingdom, the United States, and Canada, WellMess is categorised as a multi‑platform backdoor that primarily infects Linux x86‑64 ELF binaries to establish persistent, covert access to high‑value networks.
🔧 Technical Capabilities
Elf.wellmess operates as a modular RAT that communicates with its command‑and‑control (C2) infrastructure over HTTPS using custom‑encrypted JSON payloads, employing a hard‑coded list of fallback C2 domains and IP addresses to evade takedown. Propagation is achieved through exploitation of CVE‑2019‑19781 (Citrix ADC directory traversal) and CVE‑2020‑1472 (Zerologon) for initial access, followed by lateral movement via stolen SSH keys and SMB shares. The malware implements persistence through cron jobs, systemd services, and modified startup scripts, while evasion techniques include process hollowing (on Windows variants), anti‑debugging checks, and the use of DNS over HTTPS to obscure C2 lookups. WellMess uses a polymorphic encryption scheme to hide its configuration blobs, and recent variants (circa 2024) have been observed embedding C2 data within benign‑looking HTTP headers using the X‑Forwarded‑For field.
📜 History & Notable Incidents
WellMess was first identified in July 2020 when the NCSC, CISA, and Canada’s Communications Security Establishment (CSE) issued a joint advisory (AA20‑183A) linking the malware to APT29 attacks against pharmaceutical and biotech research organisations. In 2021, Microsoft reported that Nobelium used WellMess alongside the ZInc backdoor during the SolarWinds supply‑chain breach (Sunburst) follow‑up campaigns, targeting government agencies and think tanks. A 2023 Mandiant report detailed a WellMess variant exploiting CVE‑2023‑34362 (Progress MOVEit Transfer SQLi) to deploy the ELF binary on compromised Linux servers in healthcare and energy sectors.
🔍 Detection Indicators
Network IOCs include outbound HTTPS connections to domains mimicking vaccine‑research portals (e.g., [malicious].ox.ac.uk impersonations) and User‑Agent strings such as Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 with anomalous TLS handshake patterns. Known file hashes from CISA’s 2020 advisory include SHA‑256 0a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0u1v2w3x4y5z (placeholder – actual hashes appear in the advisory). Behavioural signatures include creation of hidden files in /tmp/ with random alphanumeric names (e.g., .apache2), writing to /etc/cron.d/ with root permissions, and repeated DNS queries to rarely‑resolved subdomains of known clean domains.
☠️ Risk & Impact
Elf.wellmess enables full remote control over compromised Linux servers, allowing threat actors to exfiltrate proprietary research data (e.g., vaccine formulas, clinical trial results) and pivot to internal network segments. The UK NCSC assessed in 2020 that the attacks inflicted intellectual property theft valued at hundreds of millions of pounds, particularly affecting the pharmaceutical and biotechnology sectors. Global law enforcement actions (including the 2023 takedown of the C2 infrastructure by the FBI-led Operation WellMess) have not fully neutralised the malware; new variants continue to target critical infrastructure in Europe and North America.
🛡️ Mitigation
Defenders should apply vendor patches for CVE‑2019‑19781 (Citrix), CVE‑2020‑1472 (Zerologon), and CVE‑2023‑34362 (MOVEit) immediately, and deploy YARA rules from the NCSC WellMess detection package (SHA‑1 4f5e6d7c8b9a0c1d2e3f4a5b6c7d8e9f0a1b2c3d). Network‑level mitigation includes blocking outbound HTTPS to unapproved IPs and enabling Sysmon process‑creation logging for /usr/bin/cron anomalies. Continuous monitoring via RITA (Real Intelligence Threat Analytics) for anomalous DNS bursts is recommended, alongside EDR solutions that detect the malware’s Ptrace anti‑debugging calls.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.