Exaramel is a backdoor malware family associated with the Sandworm intrusion set, including the TeleBots cluster, and is linked to operations against Ukrainian targets as well as later compromises of French organizations. Public reporting has identified both Windows and Linux variants, with strong functional overlap to tooling used in the 2016 Ukraine electric power incident and subsequent Sandworm activity. Exaramel has been observed alongside the P.A.S. webshell in long-running intrusions affecting internet-exposed Centreon servers, particularly in information technology and web hosting environments.
Exaramel provides remote administration capabilities including command execution and bidirectional file transfer. Reported variants support launching processes, writing and uploading files, executing shell commands, and updating or deleting themselves. Linux samples have been observed communicating over HTTPS and using scheduled task mechanisms such as crontab for persistence. Windows reporting also describes service-based persistence. Exaramel has additionally been described as compressing and encrypting data prior to exfiltration.
The malware family has been tied to credential collection in broader TeleBots tradecraft, and some reporting describes Exaramel itself as having credential-stealing capability, although the strongest directly supported functionality is remote access, persistence, command execution, and file exfiltration. Exaramel has been described in public reporting as originally implemented in Python and later rewritten in Rust, while separate technical reporting on Linux variants identifies Go-based ELF samples used in Sandworm-linked campaigns. Across reporting, the family is consistently characterized as a backdoor used for post-compromise access and control.
Known victimology includes non-industrial organizations, Ukrainian targets connected to TeleBots activity, and French entities compromised between 2017 and 2020, especially IT providers and web hosting companies running obsolete or exposed Centreon deployments. Exaramel is notable both as an operational implant in Sandworm campaigns and as an important technical link between TeleBots activity and the malware ecosystem surrounding the Ukraine power-grid intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A few years after the incident, ESET identified new malware, called EXARAMEL, with significant functional overlap with the 2016 Ukraine event backdoor.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
"Persistence T1503.003 Scheduled Task/Job: Cron Exaramel can use Cron" and "Logs indicating daily execution of respawner.sh by CRON were observed"
it found on them two different pieces of malware: one publicly available backdoor called PAS, and another known as Exaramel
"Persistence T1503.003 Scheduled Task/Job: Cron Exaramel can use Cron" and "Logs indicating daily execution of respawner.sh by CRON were observed"
ANSSI has been informed of an intrusion campaign targeting the monitoring software Centreon distributed by the French company CENTREON which resulted in the breach of several French entities.
"Persistence T1543 Create or Modify System Process Exaramel can use Upstart" and "Exaramel is run by root and the startup system is systemd/upstart/SystemV"
"Persistence T1503.003 Scheduled Task/Job: Cron Exaramel can use Cron" and "Logs indicating daily execution of respawner.sh by CRON were observed"
"Persistence T1543 Create or Modify System Process Exaramel can use Upstart" and "Exaramel is run by root and the startup system is systemd/upstart/SystemV"
the French agency also says it's seen overlap in command and control servers used in the Centreon hacking campaign and previous Sandworm hacking incidents.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux backdoor used for remote access and command execution, linked to advanced threat actors.
Post-compromise implant referenced as deployed after Centreon compromise; no additional functional detail provided in this text.
A backdoor found on compromised Centreon servers during the intrusion campaign affecting French entities.
A backdoor associated with Sandworm and found on compromised Centreon servers in the French intrusion campaign; an early variant previously appeared in an attack on the Ukrainian power grid.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.