Exaramel (Windows)

First seen
2018-09-01 00:00:00
Malware type
backdoor, rat
Family
Malware family
Profile updated
2026-07-07 12:44:31

Targeted industries: energy-and-utilities government-and-public-sector

Targeted regions: country_code:ua country_code:ru

Context

Exaramel is a sophisticated backdoor malware linked to the APT group TeleBots. It is known for targeting critical infrastructure within energy sectors and government institutions, primarily in Eastern Europe.

Reports & references

  • MITRE ATT&CK — G0034 (report)
  • wired.com — Sandworm Centreon Russia Hack (report)
  • ESET — New Telebots Backdoor Linking Industroyer Notpetya (report)
  • cert.ssi.gouv.fr — Certfr 2021 Cti 005 (report)
  • ESET — Eset Industry Report Government (report)
  • pylos.co — Threat Intelligence And The Limits Of Malware Analysis (report)
  • virusbulletin.com — Vb2019 Paper Rich Headers Leveraging Mysterious Artifact Pe Format (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Exaramel (report)

External references