Skip to main content

[CERT-FR] Sandworm intrusion set campaign targeting Centreon systems

0
Medium
Published: 01/27/2021 (01/27/2021, 00:00:00 UTC)
Source: CIRCL OSINT Feed
Vendor/Project: cert-ist
Product: enriched

Description

[CERT-FR] Sandworm intrusion set campaign targeting Centreon systems

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/08/2026, 04:22:05 UTC

Technical Analysis

This campaign attributed to the Sandworm intrusion set targets Centreon systems, exploiting public-facing applications to deploy web shells and establish persistence. The attackers perform file and directory discovery, use symmetric and asymmetric cryptography to secure communications, and exfiltrate data over encrypted command and control channels. The activity involves creating or modifying system processes and Windows services, indicating sophisticated post-exploitation techniques. The campaign is focused on Linux systems in Western Europe and is linked to multiple threat actors including Iridium, Telebots, and Electrum. No known exploits in the wild or patches are indicated.

Potential Impact

The campaign enables unauthorized access and control over Centreon systems, potentially leading to data exfiltration and system manipulation. The use of web shells and process modification allows persistent presence and covert operations within targeted environments. While the threat level is assessed as low by CERT-IST, the overall severity is medium due to the advanced techniques and potential impact on critical monitoring infrastructure.

Defensive Guidance

No official patches are available for this campaign as it targets Centreon systems via exploitation rather than a specific vulnerability. Organizations should monitor for indicators of compromise related to web shells and unusual process creation. Applying security best practices for public-facing applications and restricting access to Centreon management interfaces can reduce exposure. CERT-FR and CERT-IST advisories should be consulted for updated detection and response guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Uuid
60118dab-1ab8-40b2-b02b-b6f80aba047c
Original Timestamp
1729163268

Indicators of Compromise

Comment

ValueDescriptionCopy
commentBackdoors related to Sandworm
commentThese IOCs come from an ANSSI report (CERTFR-2021-CTI-004) published on February 15, 2021, which document a campaign of system compromises that impacted several French entities. This campaign targeted the Centreon IT monitoring software. The first compromises identified by the ANSSI date back from the end of 2017 and the attacks have continued until 2020. They mainly affected IT service providers, particularly web hosting providers. On the compromised systems, the webshell P.A.S. (alias Fobushell) is deployed in the Centreon web folder. Its content remains encrypted until the attacker connects to it and enters the right password. In several cases, this webshell has been used to deploy the Exaramel backdoor. This malware written in Go language is also deployed in the Centreon directory and its persistence is ensured via a scheduled task (Cron). The initial vector of this attack campaign is not precisely known. It can simply be assumed that it involves the exploitation of a vulnerability or a weakness in the Centreon monitoring software. The analyses allowed to identify two categories of infrastructure used in these attacks: Anonymization infrastructure: attackers use Tor or VPN services to connect to the webshells, Command and control infrastructure: Attackers use dedicated servers to manage the implants. Note: Exaramel communicates with its command and control servers via HTTPS. WARNING: the ANSSI does not attribute these attacks to the Sandworm group (alias Telebots) and therefore even less to a Russian intelligence unit. The similarities observed relate to the modus operandi implemented: in particular the Exaramel backdoor and infrastructure elements. In reality, these elements of similarity even seem rather weak, at least on the sole reading of the ANSSI report.
Cert-IST Description
commentExaramel
Cert-IST Malware Name
commentFobushell
Cert-IST Malware Name
commentPAS
Cert-IST Malware Name
commentP.A.S.
Cert-IST Malware Name
commentSandworm Team
Cert-IST Attack Alias
commentELECTRUM
Cert-IST Attack Alias
commentBlackEnergy
Cert-IST Attack Alias

Text

ValueDescriptionCopy
textTeleBots
Cert-IST Attack name

Link

ValueDescriptionCopy
linkhttps://wws.cert-ist.com/private/fr/IocAttack_details?format=html&objectType=ATK&ref=CERT-IST/ATK-2016-066
Cert-IST External link

File

ValueDescriptionCopy
file/tmp/.applocktx
Socket created by Exaramel
file/tmp/.applock
Socket created by Exaramel
fileconfigtx.json
Exaramel configuration file
filecentreon_module_linux_app64
filesearch.php
fileDB-Drop.php
file/bin/backup

Target location

ValueDescriptionCopy
target-locationFrance
Cert-IST Targeted Country

Datetime

ValueDescriptionCopy
datetime2021-01-26T23:00:00+00:00
Cert-IST First Disclosed Date
datetime2017-10-31T23:00:00+00:00
Cert-IST First Seen Date

Hash

ValueDescriptionCopy
hashe1ff729f45b587a5ebbc8a8a97a7923fc4ada14de4973704c9b4b89c50fd1146
hasha739f44390037b3d0a3942cd43d161a7c45fd7e7
hash92ef0aaf5f622b1253e5763f11a08857
hash893750547255b848a273bd1668e128a5e169011e79a7f5c7bb86cc5d7b2153bc
hashc69db1b120d21bd603f13006d87e817fed016667
hash84837778682450cdca43d1397afd2310
hash928d8dde63b0255feffc3d03db30aa76f7ed8913238321cc101083c2c5056ffa
hashb7afb8c91f8f9df4f18764c25251576a0f8bef6f
hasha89251cd4c15909a8e15256ead40584e
hashebe98d5e1ab6966ec1e292fafbd5ef21c2b15bd7c7bb871d8e756971b8b6877a
hash5a58e46e5b8f468445f848f8eca741eddebcef3e
hash9885fcdda12167b2f598b2d22de07d5b

Threat ID: 68367c12182aa0cae2312aeb

Added to database: 05/28/2025, 02:59:30 UTC

Last enriched: 09/08/2026, 04:22:05 UTC

Last updated: 09/10/2026, 01:52:57 UTC

Views: 198

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses