Exaramel (ELF)

First seen
2018-06-01 00:00:00
Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 12:44:39

Targeted industries: energy-and-utilities government-and-public-sector

Targeted regions: country_code:ua

Context

Exaramel is a backdoor malware identified in both Windows and Linux environments, used by the APT group TeleBots. It is known for targeting entities in Ukraine, particularly in the government and energy sectors.

Reports & references

  • MITRE ATT&CK — G0034 (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Exaramel (report)
  • wired.com — Sandworm Centreon Russia Hack (report)
  • ESET — New Telebots Backdoor Linking Industroyer Notpetya (report)
  • cert.ssi.gouv.fr — Certfr 2021 Cti 005 (report)
  • twitter.com — 1361581668092493824 (report)
  • ESET — Eset Industry Report Government (report)
  • pylos.co — Threat Intelligence And The Limits Of Malware Analysis (report)
  • domaintools.com — Centreon To Exim And Back On The Trail Of Sandworm (report)

External references