Gelsemium is a stealthy cyber-espionage threat actor active since at least 2014 and widely assessed as China-aligned, though formal state attribution has remained limited in some reporting. The group has targeted organizations in East Asia, Southeast Asia, and the Middle East, with victim sectors including government, religious organizations, electronics manufacturers, universities, and other strategic entities. Reporting has also linked Gelsemium-associated activity to compromises of Microsoft Exchange and IIS infrastructure, including use of the SessionManager IIS backdoor and OwlProxy-family tooling in espionage operations. Gelsemium is known for custom malware development and quiet post-compromise tradecraft. Malware and tooling associated with the actor include Gelsevirine, SessionManager, OwlProxy, WolfsBane, and FireWood, with some reporting also noting overlap or shared techniques with other China-aligned tooling ecosystems. The group has used HTTP and HTTPS for command-and-control, custom shellcode to manually map embedded DLLs into memory, encrypted or compressed payload components, and anti-analysis measures such as junk code insertion to obscure behavior. Observed capabilities include security software discovery, command execution, file operations, proxying and tunneling, and long-term persistence on compromised servers. On Windows, Gelsemium-associated malware has demonstrated privilege-escalation techniques including User Account Control bypass and token manipulation. In server-side intrusions, the actor has been observed maintaining access through web shells, IIS-native backdoors, and service-based persistence, followed by reconnaissance, lateral movement, and deployment of additional post-exploitation tooling. SessionManager supports remote command execution, file transfer, and socket-based proxying, while OwlProxy variants provide encrypted command execution and multi-stage proxy functionality for reaching internal systems. Victimology and tooling indicate an intelligence-collection mission focused on persistent access to sensitive networks rather than disruptive or financially motivated operations. Known aliases and related names in malware reporting primarily center on the Gelsemium designation itself, with associated malware families and backdoors including Gelsevirine, WolfsBane, FireWood, SessionManager, and OwlProxy.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
22 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Gelsemium is associated with the deployment of the FireWood backdoor, which uses a kernel driver rootkit module to hide processes and execute attacker commands.
Gelsemium is a Chinese APT group associated with the use of privilege escalation tools such as JuicyPotato/SweetPotato, and has been linked to attacks leveraging SAP NetWeaver vulnerabilities.
Referenced in connection with a Linux backdoor named WolfsBane.
Cyber-espionage activity against Southeast Asian government IIS servers, establishing stealthy footholds via web shells, deploying custom IIS backdoors/proxy tooling (SessionManager, OwlProxy), and using tunneling/C2 frameworks (EarthWorm, Cobalt Strike) plus privilege-escalation tooling to expand access and collect intelligence.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.