France’s cybersecurity agency ANSSI linked a multiyear intrusion campaign against several French organizations to the Russian GRU-associated Sandworm group, saying the attackers primarily compromised IT firms and web hosting providers between 2017 and 2020. Investigators said the victims were running obsolete, unsupported open-source Centreon software, and that some intrusions may have remained undetected for years. Centreon disputed broader implications for its customer base, arguing the affected deployments were insecure and unsupported and that the number of identified targets was limited.
ANSSI reported the deployment of the PAS backdoor and Exaramel malware, with command-and-control overlaps tying the activity to earlier Sandworm operations. Exaramel has previously been associated with the TeleBots toolset linked to Sandworm, reinforcing attribution to the same Russian military hacking apparatus behind disruptive campaigns such as NotPetya and Industroyer. Although French authorities did not identify a definitive end goal in this operation, the malware links and Sandworm’s history raised concern that the campaign went beyond routine espionage.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
ANSSI said the intrusion campaign persisted until 2020 and may have remained undetected for as long as three years. The agency said it could not determine the initial intrusion method used to compromise the Centreon servers.
ANSSI said a long-running intrusion campaign linked to the Russian GRU-associated Sandworm group began in late 2017 and targeted several French organizations, mostly IT firms and web hosting companies. The intrusions involved compromised servers running obsolete open-source Centreon software.
Centreon said no actual Centreon customers were affected, arguing the victims used an unsupported open-source version that had been obsolete for more than five years and was insecurely configured. The company said it was contacting customers and partners and recommended that anyone still using obsolete versions upgrade or seek assistance.
ANSSI published an advisory warning that hackers linked to Sandworm had breached several French organizations. The report described the victims as mostly IT firms and especially web hosting companies.
During the campaign, ANSSI found the PAS backdoor and Exaramel malware on compromised servers. It also observed command-and-control overlap with prior Sandworm activity, supporting the attribution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.