The Gelsemium group is a little-known threat actor targeting government and religious entities across East Asia and the Middle East.
Analyst brief
The Gelsemium group has been active since at least 2014, though its type remains unknown. It primarily targets government, electronics manufacturers, universities, and religious organizations across East Asia and the Middle East. The main TTPs and tools involve custom malware components named Gelsemine, Gelsenicine, and Gelsevirine. Defenders should focus on continuous network monitoring, email security, and detection of these specific malicious processes.
Gelsemium
狼毒草
unknown
The Gelsemium group has been active since at least 2014 and was described in the past by a few security companies. Gelsemium’s name comes from one possible translation ESET found while reading a report from VenusTech who dubbed the group 狼毒草 for the first time. It’s the name of a genus of flowering plants belonging to the family Gelsemiaceae, Gelsemium elegans is the species that contains toxic compounds like Gelsemine, Gelsenicine and Gelsevirine, which ESET choses as names for the three components of this malware family.