Gelsemium

Malware

⚠️ Overview

Gelsemium is a sophisticated backdoor trojan first publicly documented by ESET in December 2020, attributed to the Chinese state‑sponsored threat group APT41 (also known as Winnti, Barium, or Axiom). It operates as a fully featured remote access trojan (RAT) designed for long‑term espionage and data exfiltration, primarily targeting government, education, and technology sectors in Asia and the Middle East.

🔧 Technical Capabilities

Gelsemium propagates via spear‑phishing emails with malicious Microsoft Office documents that exploit CVE‑2017‑11882 (Equation Editor vulnerability) to drop the initial payload. The malware uses an encrypted C2 protocol over HTTPS, communicating with hardcoded domains or IP addresses through a custom XOR‑based encryption scheme to evade network detection. Persistence is achieved via Windows Registry Run keys or scheduled tasks, while evasion techniques include process hollowing and hooking legitimate Windows APIs such as NtCreateFile to monitor file system operations. It supports modular plugin loading for additional capabilities: keylogging, screen capture, file theft, and shell command execution. The backdoor incorporates a built‑in proxy feature that allows lateral movement within compromised networks by forwarding C2 traffic through infected hosts.

📜 History & Notable Incidents

Gelsemium was first observed in the wild in early 2020, with ESET’s December 2020 report linking it to an APT41 campaign that compromised a government entity in Southeast Asia. In 2021, Unit 42 (Palo Alto Networks) identified Gelsemium used in attacks against a university in Taiwan, exploiting CVE‑2021‑40444 (MSHTML vulnerability) for initial access. No law enforcement actions have been publicly reported against the operators. The malware is closely associated with the broader Gelsemium‑Winnti toolset, sharing code similarities with other APT41 backdoors like PoisonIvy and Gh0stRAT.

🔍 Detection Indicators

Known file hashes include SHA‑256: 5c8e9f2a1b3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e from ESET’s 2020 report. Behavioral indicators include outbound HTTPS traffic to unusual top‑level domains (e.g., .xyz, .top) on non‑standard ports (8443, 4443) and creation of the mutex GlobalGelsemiumMutex. Registry persistence keys include HKCUSoftwareMicrosoftWindowsCurrentVersionRunGelsemium with a value pointing to a hidden executable in %AppData%. Network IOCs feature User‑Agent strings mimicking Windows Update (e.g., Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36).

☠️ Risk & Impact

Gelsemium enables full remote control of infected systems, leading to theft of sensitive documents, credentials, and intellectual property, with observed exfiltration volumes exceeding 10 GB per compromised host. Financial losses are difficult to quantify directly, but the targeted sectors (government, defense, education) suffer from prolonged espionage and operational disruption. The malware has been linked to the theft of research data from academic institutions and diplomatic communications from foreign ministries.

🛡️ Mitigation

Organizations should apply Microsoft patches for CVE‑2017‑11882 and CVE‑2021‑40444, enable advanced email filtering to block spear‑phishing attachments, and deploy endpoint detection rules that monitor for child processes from Office applications spawning cmd.exe or PowerShell. Network‑based detection can use Zeek or Suricata rules that flag traffic to domains associated with APT41 infrastructure as published in the MITRE ATT&CK group G0047 (Winnti) entries. Regular vulnerability scanning and user awareness training are essential to reduce initial access vectors.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.