Sandworm intrusion set campaign targeting Centreon systems
ID: 9a5e4f34-4c9d-43a7-8d7a-8fc85c054f40
STIX ID: report--9a5e4f34-4c9d-43a7-8d7a-8fc85c054f40
Threat Score
85/100
Uploaded: 2026-07-30
Published Date: 2026-07-30
Last Modified Date: 2026-08-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:A1
...
...
**ANSSI report (27/01/2021):** Technical analysis of a multi-year intrusion campaign targeting Centreon monitoring servers that deployed the P.A.S. PHP webshell and the Exaramel Go backdoor, affecting several French entities (notably IT and hosting providers); the document provides malware code analysis, persistence and C2 infrastructure details, YARA/Snort detection rules, IOCs, recommended mitigations, and assessments linking the campaign to the Sandworm/TeleBots intrusion set.
