Exaramel for Linux
MITRE ATT&CK: S0401 View on attack.mitre.org
Aliases: Exaramel for Linux
- First seen
- 2018-09-19 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- linux
- Profile updated
- 2026-07-07 14:24:41
Targeted industries: government-and-public-sector energy-and-utilities transportation-and-logistics
Context
Exaramel for Linux is a backdoor written in the Go Programming Language and compiled as a 64-bit ELF binary. The Windows version is tracked separately under Exaramel for Windows.
Detection coverage
- 194 Sigma rules
Malware & tools used
- Ingress Tool Transfer (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Web Protocols (attack-pattern)
- Create or Modify System Process (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Fallback Channels (attack-pattern)
- Systemd Service (attack-pattern)
- File Deletion (attack-pattern)
- Setuid and Setgid (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Unix Shell (attack-pattern)
- Cron (attack-pattern)
Used by threat actors
- Sandworm Team (threat-actor)
Reports & references
- ESET — New Telebots Backdoor Linking Industroyer Notpetya (report)
- MITRE ATT&CK — S0401 (report)
External references
- mitre-attack — S0401
- Exaramel for Linux
- ESET TeleBots Oct 2018
- misp-galaxy
- misp-galaxy