Exaramel (ELF)
- First seen
- 2018-06-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Profile updated
- 2026-07-07 12:44:39
Targeted industries: energy-and-utilities government-and-public-sector
Targeted regions: country_code:ua
Context
Exaramel is a backdoor malware identified in both Windows and Linux environments, used by the APT group TeleBots. It is known for targeting entities in Ukraine, particularly in the government and energy sectors.
Reports & references
- MITRE ATT&CK — G0034 (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Exaramel (report)
- wired.com — Sandworm Centreon Russia Hack (report)
- ESET — New Telebots Backdoor Linking Industroyer Notpetya (report)
- cert.ssi.gouv.fr — Certfr 2021 Cti 005 (report)
- twitter.com — 1361581668092493824 (report)
- ESET — Eset Industry Report Government (report)
- pylos.co — Threat Intelligence And The Limits Of Malware Analysis (report)
- domaintools.com — Centreon To Exim And Back On The Trail Of Sandworm (report)