{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/centreon-monitoring-software/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Centreon (monitoring software)"],"_cs_severities":["high"],"_cs_tags":["centreon","webshell","backdoor","persistence","monitoring"],"_cs_type":"advisory","_cs_vendors":["Centreon"],"content_html":"\u003cp\u003eBetween 2017 and 2020, threat actors targeted entities using Centreon IT monitoring software, with a focus on web hosting providers and IT service organizations. The campaign involved unauthorized access to Centreon servers, leading to the deployment of the P.A.S. (Fobushell) webshell within the Centreon web directory. This webshell served as the primary entry point for manual interaction and follow-on malicious activity. In several identified cases, the actors deployed the Exaramel backdoor, a malware written in the Go programming language, to further strengthen their control over the compromised systems. Exaramel achieved persistence through scheduled cron tasks and communicated with external command-and-control (C2) infrastructure via HTTPS. The attackers utilized anonymization services, including Tor and commercial VPNs, to obfuscate their connection to the deployed webshells. While the report mentions similarities in TTPs to the Sandworm intrusion set, the French national cybersecurity agency (ANSSI) noted that these attributions remain inconclusive due to the limited nature of the shared operational elements.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial exploitation of unknown vulnerabilities or weaknesses in the target Centreon installation.\u003c/li\u003e\n\u003cli\u003eUnauthorized file upload of the P.A.S. (Fobushell) webshell into the Centreon web directory.\u003c/li\u003e\n\u003cli\u003eAuthentication to the webshell using a predefined password to execute arbitrary commands.\u003c/li\u003e\n\u003cli\u003eDeployment of the Exaramel backdoor (Go-based) into the Centreon directory.\u003c/li\u003e\n\u003cli\u003eEstablishment of persistence for the Exaramel backdoor using a Linux Cron scheduled task.\u003c/li\u003e\n\u003cli\u003eConfiguration of Exaramel via local files (e.g., configtx.json) and creation of temporary socket files in /tmp/ for communication.\u003c/li\u003e\n\u003cli\u003eExfiltration or command execution via Exaramel communicating with C2 servers over HTTPS.\u003c/li\u003e\n\u003cli\u003eUse of Tor or VPN services by operators to obscure management of the webshell and C2 channels.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe campaign resulted in the compromise of several French entities, particularly IT service providers and web hosting firms. Successful exploitation allowed attackers to maintain persistent, long-term access to critical infrastructure monitoring systems, posing significant risks of data exfiltration, lateral movement within the provider's network, and potential disruption of monitoring services for downstream clients.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification and removal of unauthorized files within the Centreon directory structure and monitor for suspicious scheduled tasks.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy file integrity monitoring (FIM) on the Centreon web directory to detect unauthorized additions of PHP or binary files.\u003c/li\u003e\n\u003cli\u003eAudit existing cron jobs on all Centreon monitoring servers for unexpected execution paths.\u003c/li\u003e\n\u003cli\u003eImplement network egress filtering to restrict unauthorized HTTPS traffic from monitoring servers to known Tor exit nodes or unapproved VPN endpoints.\u003c/li\u003e\n\u003cli\u003eScan the /tmp/ directory for artifacts associated with Exaramel, such as files named .applock or .applocktx.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-29T19:11:55Z","date_published":"2026-08-29T19:11:55Z","id":"https://feed.craftedsignal.io/briefs/2026-08-centreon-campaign/","summary":"Between 2017 and 2020, threat actors targeted Centreon environments at IT service providers by deploying the P.A.S. webshell and the Exaramel backdoor.","title":"Historical Campaign Targeting Centreon IT Monitoring Software","url":"https://feed.craftedsignal.io/briefs/2026-08-centreon-campaign/"}],"language":"en","title":"CraftedSignal Threat Feed - Centreon (Monitoring Software)","version":"https://jsonfeed.org/version/1.1"}