logo

Sandworm intrusion set campaign targeting Centreon systems

ID: 9a5e4f34-4c9d-43a7-8d7a-8fc85c054f40

STIX ID: report--9a5e4f34-4c9d-43a7-8d7a-8fc85c054f40

Threat Score

85/100

Uploaded: 2026-07-30

Published Date: 2026-07-30

Last Modified Date: 2026-08-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:A1
...
...
**ANSSI report (27/01/2021):** Technical analysis of a multi-year intrusion campaign targeting Centreon monitoring servers that deployed the P.A.S. PHP webshell and the Exaramel Go backdoor, affecting several French entities (notably IT and hosting providers); the document provides malware code analysis, persistence and C2 infrastructure details, YARA/Snort detection rules, IOCs, recommended mitigations, and assessments linking the campaign to the Sandworm/TeleBots intrusion set.