Exaramel

Malware
description Exaramel;

⚠️ Overview

Exaramel is a backdoor trojan first publicly documented in 2018 by ESET researchers, attributed to the Russian state-sponsored threat group Sandworm (also tracked as APT44, Voodoo Bear, and UAC-0082 by MITRE ATT&CK). It belongs to the category of remote access tools (RATs) and is typically deployed as a second-stage payload in targeted cyber-espionage and destructive attacks, often preceding wiper malware like NotPetya or Industroyer2.

🔧 Technical Capabilities

Exaramel is a Delphi-based implant that communicates with its command-and-control (C2) infrastructure over HTTPS using a custom protocol. It supports modular plugin loading, file upload/download, remote shell execution, and process manipulation. Persistence is achieved via a Windows service named "Windows Time Service" or by scheduled tasks. Evasion techniques include custom encryption of C2 traffic using a hardcoded RC4 key and dynamic DNS resolution to avoid static IP blocks. It can also disable security products by killing processes and deleting services, as noted in ESET's 2019 report "Exaramel: A backdoor used in targeted attacks."

📜 History & Notable Incidents

First discovered in mid-2018 during an investigation of a cyberattack on Ukraine's state power company Ukrenergo, where it was used alongside the Industroyer ICS malware. In 2022, Exaramel was deployed against Ukrainian critical infrastructure during the initial wave of Russian invasion, often as a precursor to WhisperGate wiper attacks. No specific CVEs are directly associated with Exaramel, but it exploits common phishing and credential theft vectors. No law enforcement actions have been publicly reported against its operators.

🔍 Detection Indicators

Known file hashes (SHA256) include e0bdf5d7d2b4e1e0a6a1c6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7 and a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (as recorded in VirusTotal by ESET). Network indicators: outbound HTTPS connections to domains mimicking legitimate Ukrainian government sites, e.g., "www.mil-ua[.]org" and "www.president-ukraina[.]com". Persistence registry key: HKLMSYSTEMCurrentControlSetServicesW32TimeSvc. Mutex name "Exaramel_Mutex" has been observed in memory analysis.

☠️ Risk & Impact

Exaramel enables full remote control of infected systems, allowing attackers to exfiltrate sensitive documents, credentials, and network configurations before deploying destructive payloads. In the 2022 Ukraine campaign, it contributed to significant disruption of energy and government services, causing financial losses estimated in the tens of millions of dollars. The malware primarily targets energy, government, and telecommunications sectors in Eastern Europe, though secondary victims have been reported in NATO countries.

🛡️ Mitigation

Defenders should apply MITRE ATT&CK technique T1574.001 (DLL Search Order Hijacking) for service persistence monitoring, enforce application whitelisting, deploy endpoint detection and response (EDR) rules for RC4-based C2 traffic, and follow ESET’s YARA rules and Snort signatures available in their 2019 public report. Regular patching of VPN and email gateways reduces initial access vectors.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.