Exaramel for Windows
MITRE ATT&CK: S0343 View on attack.mitre.org
Aliases: Exaramel for Windows
- First seen
- 2018-04-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 14:24:43
Targeted industries: government-and-public-sector energy-and-utilities
Targeted regions: country_code:sk country_code:cz country_code:ua
Context
Exaramel for Windows is a backdoor used for targeting Windows systems. The Linux version is tracked separately under Exaramel for Linux.
Detection coverage
- 174 Sigma rules
Malware & tools used
- Archive Collected Data (attack-pattern)
- Visual Basic (attack-pattern)
- Fileless Storage (attack-pattern)
- Windows Service (attack-pattern)
- Modify Registry (attack-pattern)
- Windows Command Shell (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Local Data Staging (attack-pattern)
Used by threat actors
- Sandworm Team (threat-actor)
Reports & references
- ESET — New Telebots Backdoor Linking Industroyer Notpetya (report)
- MITRE ATT&CK — S0343 (report)
External references
- mitre-attack — S0343
- Exaramel for Windows
- ESET TeleBots Oct 2018
- misp-galaxy
- misp-galaxy