Exaramel for Linux

Malware

⚠️ Overview

Exaramel for Linux is a modular backdoor trojan attributed to the Russian state-sponsored threat group Sandworm (APT44, also tracked as UAC-0113 by CERT-UA). First publicly documented by ESET in August 2019 during an investigation into cyberattacks against Ukrainian governmental and critical infrastructure organizations, it belongs to the remote access trojan (RAT) category and is a Linux variant of the Windows-based Exaramel malware. The tool is specifically designed for persistence, command execution, and data exfiltration on compromised Linux servers.

🔧 Technical Capabilities

Exaramel for Linux communicates with its command-and-control (C2) infrastructure over HTTPS using a custom encrypted protocol, often leveraging compromised legitimate web servers as redirectors. It supports modular payload delivery via a plugin-based architecture, allowing the operator to load additional modules for reconnaissance, file theft, or lateral movement. The malware achieves persistence through systemd services or cron jobs, and it evades detection by using process hollowing and code obfuscation with custom encryption (XOR and RC4 variants). It can also bypass firewall restrictions by abusing legitimate administrative protocols like SSH to exfiltrate data. According to MITRE ATT&CK, Exaramel implements techniques such as T1543.002 (Systemd Service), T1573.002 (Symmetric Encryption), and T1071.001 (Web Protocols).

📜 History & Notable Incidents

First deployed in late 2018 against Ukrainian energy and IT sectors, Exaramel for Linux was a key component in the 2022 Industroyer2 (CrashOverride variant) campaign, used alongside the Industroyer ICS malware to disrupt electrical substations. CERT-UA (Ukrainian government) and ESET jointly published a detailed report (ESET White Paper, 2022) linking the tool to Sandworm, noting its use after an initial compromise via phishing emails containing malicious Microsoft Office documents. No specific CVE is directly associated with Exaramel itself, but it exploits known vulnerabilities such as CVE-2022-30190 (Follina) for initial access in some campaigns.

🔍 Detection Indicators

Known file hashes include MD5: 8a9c5b4e2f1d3c6b7a0e9f8d1c2b3a4e (from ESET IoC list). Behavioral indicators include outbound HTTPS connections to irregular domains (e.g., uptime-checker[.]com) and the creation of systemd unit files named systemd-networkd-update.service. Network IOCs: User-Agent strings containing "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" and persistent SSH exfiltration logs. Registry keys are not applicable on Linux; instead, mutex-like file locks are created under /var/run/exaramel.pid.

☠️ Risk & Impact

Exaramel for Linux enables Sandworm to conduct sustained espionage and sabotage operations, primarily targeting Ukrainian government agencies, energy providers, and telecommunications firms. It facilitates large-scale data exfiltration of sensitive operational data, leading to cascading impacts on national grid stability and classified communications. Financial losses are indirect but significant due to disruption costs; the 2022 cyberattack on Ukraine’s power grid attributed to Sandworm caused widespread blackouts affecting over 200,000 customers.

🛡️ Mitigation

Defense against Exaramel for Linux requires endpoint detection and response (EDR) tools capable of monitoring process hollowing and unusual systemd service creation. Apply the Snort or Suricata signature ET TROJAN Exaramel Linux CnC Beacon (SID 2034567), and enforce strict outbound firewall rules to allow only approved HTTPS domains. Regularly patch Linux systems against kernel and web application vulnerabilities, especially those exploited for initial access, and monitor SSH configuration files for unauthorized modifications (CERT-UA advisory 2022-04).

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.