[CERT-FR] Sandworm intrusion set campaign targeting Centreon systems
[CERT-FR] Sandworm intrusion set campaign targeting Centreon systems
AI Analysis
Technical Summary
This campaign attributed to the Sandworm intrusion set targets Centreon systems, exploiting public-facing applications to deploy web shells and establish persistence. The attackers perform file and directory discovery, use symmetric and asymmetric cryptography to secure communications, and exfiltrate data over encrypted command and control channels. The activity involves creating or modifying system processes and Windows services, indicating sophisticated post-exploitation techniques. The campaign is focused on Linux systems in Western Europe and is linked to multiple threat actors including Iridium, Telebots, and Electrum. No known exploits in the wild or patches are indicated.
Potential Impact
The campaign enables unauthorized access and control over Centreon systems, potentially leading to data exfiltration and system manipulation. The use of web shells and process modification allows persistent presence and covert operations within targeted environments. While the threat level is assessed as low by CERT-IST, the overall severity is medium due to the advanced techniques and potential impact on critical monitoring infrastructure.
Mitigation Recommendations
No official patches are available for this campaign as it targets Centreon systems via exploitation rather than a specific vulnerability. Organizations should monitor for indicators of compromise related to web shells and unusual process creation. Applying security best practices for public-facing applications and restricting access to Centreon management interfaces can reduce exposure. CERT-FR and CERT-IST advisories should be consulted for updated detection and response guidance.
Indicators of Compromise
- comment: Backdoors related to Sandworm
- text: TeleBots
- link: https://wws.cert-ist.com/private/fr/IocAttack_details?format=html&objectType=ATK&ref=CERT-IST/ATK-2016-066
- comment: These IOCs come from an ANSSI report (CERTFR-2021-CTI-004) published on February 15, 2021, which document a campaign of system compromises that impacted several French entities. This campaign targeted the Centreon IT monitoring software. The first compromises identified by the ANSSI date back from the end of 2017 and the attacks have continued until 2020. They mainly affected IT service providers, particularly web hosting providers. On the compromised systems, the webshell P.A.S. (alias Fobushell) is deployed in the Centreon web folder. Its content remains encrypted until the attacker connects to it and enters the right password. In several cases, this webshell has been used to deploy the Exaramel backdoor. This malware written in Go language is also deployed in the Centreon directory and its persistence is ensured via a scheduled task (Cron). The initial vector of this attack campaign is not precisely known. It can simply be assumed that it involves the exploitation of a vulnerability or a weakness in the Centreon monitoring software. The analyses allowed to identify two categories of infrastructure used in these attacks: Anonymization infrastructure: attackers use Tor or VPN services to connect to the webshells, Command and control infrastructure: Attackers use dedicated servers to manage the implants. Note: Exaramel communicates with its command and control servers via HTTPS. WARNING: the ANSSI does not attribute these attacks to the Sandworm group (alias Telebots) and therefore even less to a Russian intelligence unit. The similarities observed relate to the modus operandi implemented: in particular the Exaramel backdoor and infrastructure elements. In reality, these elements of similarity even seem rather weak, at least on the sole reading of the ANSSI report.
- file: /tmp/.applocktx
- file: /tmp/.applock
- file: configtx.json
- target-location: France
- comment: Exaramel
- comment: Fobushell
- comment: PAS
- comment: P.A.S.
- comment: Sandworm Team
- comment: ELECTRUM
- comment: BlackEnergy
- datetime: 2021-01-26T23:00:00+00:00
- datetime: 2017-10-31T23:00:00+00:00
- file: centreon_module_linux_app64
- hash: e1ff729f45b587a5ebbc8a8a97a7923fc4ada14de4973704c9b4b89c50fd1146
- hash: a739f44390037b3d0a3942cd43d161a7c45fd7e7
- hash: 92ef0aaf5f622b1253e5763f11a08857
- file: search.php
- hash: 893750547255b848a273bd1668e128a5e169011e79a7f5c7bb86cc5d7b2153bc
- hash: c69db1b120d21bd603f13006d87e817fed016667
- hash: 84837778682450cdca43d1397afd2310
- file: DB-Drop.php
- hash: 928d8dde63b0255feffc3d03db30aa76f7ed8913238321cc101083c2c5056ffa
- hash: b7afb8c91f8f9df4f18764c25251576a0f8bef6f
- hash: a89251cd4c15909a8e15256ead40584e
- file: /bin/backup
- hash: ebe98d5e1ab6966ec1e292fafbd5ef21c2b15bd7c7bb871d8e756971b8b6877a
- hash: 5a58e46e5b8f468445f848f8eca741eddebcef3e
- hash: 9885fcdda12167b2f598b2d22de07d5b
[CERT-FR] Sandworm intrusion set campaign targeting Centreon systems
Description
[CERT-FR] Sandworm intrusion set campaign targeting Centreon systems
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This campaign attributed to the Sandworm intrusion set targets Centreon systems, exploiting public-facing applications to deploy web shells and establish persistence. The attackers perform file and directory discovery, use symmetric and asymmetric cryptography to secure communications, and exfiltrate data over encrypted command and control channels. The activity involves creating or modifying system processes and Windows services, indicating sophisticated post-exploitation techniques. The campaign is focused on Linux systems in Western Europe and is linked to multiple threat actors including Iridium, Telebots, and Electrum. No known exploits in the wild or patches are indicated.
Potential Impact
The campaign enables unauthorized access and control over Centreon systems, potentially leading to data exfiltration and system manipulation. The use of web shells and process modification allows persistent presence and covert operations within targeted environments. While the threat level is assessed as low by CERT-IST, the overall severity is medium due to the advanced techniques and potential impact on critical monitoring infrastructure.
Defensive Guidance
No official patches are available for this campaign as it targets Centreon systems via exploitation rather than a specific vulnerability. Organizations should monitor for indicators of compromise related to web shells and unusual process creation. Applying security best practices for public-facing applications and restricting access to Centreon management interfaces can reduce exposure. CERT-FR and CERT-IST advisories should be consulted for updated detection and response guidance.
Technical Details
- Uuid
- 60118dab-1ab8-40b2-b02b-b6f80aba047c
- Original Timestamp
- 1729163268
Indicators of Compromise
Comment
| Value | Description | Copy |
|---|---|---|
commentBackdoors related to Sandworm | — | |
commentThese IOCs come from an ANSSI report (CERTFR-2021-CTI-004) published on February 15, 2021, which document a campaign of system compromises that impacted several French entities. This campaign targeted the Centreon IT monitoring software.
The first compromises identified by the ANSSI date back from the end of 2017 and the attacks have continued until 2020. They mainly affected IT service providers, particularly web hosting providers.
On the compromised systems, the webshell P.A.S. (alias Fobushell) is deployed in the Centreon web folder. Its content remains encrypted until the attacker connects to it and enters the right password.
In several cases, this webshell has been used to deploy the Exaramel backdoor. This malware written in Go language is also deployed in the Centreon directory and its persistence is ensured via a scheduled task (Cron).
The initial vector of this attack campaign is not precisely known. It can simply be assumed that it involves the exploitation of a vulnerability or a weakness in the Centreon monitoring software.
The analyses allowed to identify two categories of infrastructure used in these attacks:
Anonymization infrastructure: attackers use Tor or VPN services to connect to the webshells,
Command and control infrastructure: Attackers use dedicated servers to manage the implants.
Note: Exaramel communicates with its command and control servers via HTTPS.
WARNING: the ANSSI does not attribute these attacks to the Sandworm group (alias Telebots) and therefore even less to a Russian intelligence unit. The similarities observed relate to the modus operandi implemented: in particular the Exaramel backdoor and infrastructure elements. In reality, these elements of similarity even seem rather weak, at least on the sole reading of the ANSSI report. | Cert-IST Description | |
commentExaramel | Cert-IST Malware Name | |
commentFobushell | Cert-IST Malware Name | |
commentPAS | Cert-IST Malware Name | |
commentP.A.S. | Cert-IST Malware Name | |
commentSandworm Team | Cert-IST Attack Alias | |
commentELECTRUM | Cert-IST Attack Alias | |
commentBlackEnergy | Cert-IST Attack Alias |
Text
| Value | Description | Copy |
|---|---|---|
textTeleBots | Cert-IST Attack name |
Link
| Value | Description | Copy |
|---|---|---|
linkhttps://wws.cert-ist.com/private/fr/IocAttack_details?format=html&objectType=ATK&ref=CERT-IST/ATK-2016-066 | Cert-IST External link |
File
| Value | Description | Copy |
|---|---|---|
file/tmp/.applocktx | Socket created by Exaramel | |
file/tmp/.applock | Socket created by Exaramel | |
fileconfigtx.json | Exaramel configuration file | |
filecentreon_module_linux_app64 | — | |
filesearch.php | — | |
fileDB-Drop.php | — | |
file/bin/backup | — |
Target location
| Value | Description | Copy |
|---|---|---|
target-locationFrance | Cert-IST Targeted Country |
Datetime
| Value | Description | Copy |
|---|---|---|
datetime2021-01-26T23:00:00+00:00 | Cert-IST First Disclosed Date | |
datetime2017-10-31T23:00:00+00:00 | Cert-IST First Seen Date |
Hash
| Value | Description | Copy |
|---|---|---|
hashe1ff729f45b587a5ebbc8a8a97a7923fc4ada14de4973704c9b4b89c50fd1146 | — | |
hasha739f44390037b3d0a3942cd43d161a7c45fd7e7 | — | |
hash92ef0aaf5f622b1253e5763f11a08857 | — | |
hash893750547255b848a273bd1668e128a5e169011e79a7f5c7bb86cc5d7b2153bc | — | |
hashc69db1b120d21bd603f13006d87e817fed016667 | — | |
hash84837778682450cdca43d1397afd2310 | — | |
hash928d8dde63b0255feffc3d03db30aa76f7ed8913238321cc101083c2c5056ffa | — | |
hashb7afb8c91f8f9df4f18764c25251576a0f8bef6f | — | |
hasha89251cd4c15909a8e15256ead40584e | — | |
hashebe98d5e1ab6966ec1e292fafbd5ef21c2b15bd7c7bb871d8e756971b8b6877a | — | |
hash5a58e46e5b8f468445f848f8eca741eddebcef3e | — | |
hash9885fcdda12167b2f598b2d22de07d5b | — |
Threat ID: 68367c12182aa0cae2312aeb
Added to database: 05/28/2025, 02:59:30 UTC
Last enriched: 09/08/2026, 04:22:05 UTC
Last updated: 09/10/2026, 01:52:57 UTC
Views: 198
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.