Exaramel (Windows)
- First seen
- 2018-09-01 00:00:00
- Malware type
- backdoor, rat
- Family
- Malware family
- Profile updated
- 2026-07-07 12:44:31
Targeted industries: energy-and-utilities government-and-public-sector
Targeted regions: country_code:ua country_code:ru
Context
Exaramel is a sophisticated backdoor malware linked to the APT group TeleBots. It is known for targeting critical infrastructure within energy sectors and government institutions, primarily in Eastern Europe.
Reports & references
- MITRE ATT&CK — G0034 (report)
- wired.com — Sandworm Centreon Russia Hack (report)
- ESET — New Telebots Backdoor Linking Industroyer Notpetya (report)
- cert.ssi.gouv.fr — Certfr 2021 Cti 005 (report)
- ESET — Eset Industry Report Government (report)
- pylos.co — Threat Intelligence And The Limits Of Malware Analysis (report)
- virusbulletin.com — Vb2019 Paper Rich Headers Leveraging Mysterious Artifact Pe Format (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Exaramel (report)