Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Gelsemium

Also known as: 狼毒草

Description

The Gelsemium group has been active since at least 2014 and was described in the past by a few security companies. Gelsemium’s name comes from one possible translation ESET found while reading a report from VenusTech who dubbed the group 狼毒草 for the first time. It’s the name of a genus of flowering plants belonging to the family Gelsemiaceae, Gelsemium elegans is the species that contains toxic compounds like Gelsemine, Gelsenicine and Gelsevirine, which ESET choses as names for the three components of this malware family.

Goals & Targeting

Targeted Sectors

Government

AI Analysis

· 1 week ago

Executive Summary

Gelsemium, also known as 狼毒草, is an advanced persistent threat (APT) group active since at least 2014. This group is primarily associated with a sophisticated malware family named after toxic compounds found in the Gelsemium genus of plants. Targeting government sectors, Gelsemium likely operates to achieve espionage or data theft objectives.

Goals & Targeting

Gelsemium targets government entities, likely to gather intelligence or sensitive data. Their strategic focus on such sectors indicates potential interests in state secrets, defense information, and political activities. The group's objectives seem aligned with typical APT behavior, possibly for espionage or influence operations.

Enhanced Description

Gelsemium, referred to as 狼毒草 by Chinese researchers, has been active since at least 2014, according to ESET. The group's name originates from toxic compounds in the Gelsemiaceae family, specifically Gelsemium elegans, which contains harmful alkaloids. ESET noted the malware components named after these toxins and linked them to Gelsemium activities. While their specific origins remain unclear, the group's targeting of government sectors suggests possible state-sponsored or politically motivated activity.

Key Capabilities

  • Gelsmine
  • Gelsenicine
  • Gelsevirine

MITRE ATT&CK Tactics

Initial Access
Persistence

ATT&CK Techniques

T1025
T1003

Software / Tooling

Gelsmine
Gelsenicine
Gelsevirine

Campaigns & Victims

Gelsemium has been observed targeting government sectors through tailored attacks. While specific campaign details are limited, their activity spans several years with a focus on maintaining persistence and data collection.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Custom malware components

Recommended Actions

  • Implement robust email filtering to detect spear-phishing attempts.
  • Monitor network traffic for signs of persistent threat activity.
  • Regularly update systems and apply patches to mitigate vulnerabilities.

Suggested Tags

APT
espionage
government

Confidence Assessment

Gelsemium's exact origins, targeting countries beyond government sectors, and specific TTPs remain uncertain. Despite these gaps, the malware family and ESET's analysis provide foundational insights into their operations.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
espionage
government

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.