In 2021, the ANSSI (Agence nationale de la sécurité des systèmes d'information) published an advisory warning that hackers with links to Sandworm, a group within Russia's GTsST, had breached several French organizations. The agency describes those victims as "mostly" IT firms and particularly web hosting companies. ANSSI states the intrusion campaign dates back to late 2017 and continued until 2020. There were three types of payloads present on the compromised machines used by the attackers that are included in this chain.
Learn more about this chain at https://feed.prelude.org/
TTP Tuesday chains are a part of Prelude's Professional and Enterprise license learn more at https://www.prelude.org/enterprise
Timestamps:
0:00 Prelude
0:06 Introduction and Intel Brief Start
0:20 Sandworm Group Explanation
0:47 Centreon
1:10 ANSSI
1:22 Exaramel Malware
2:00 Exaramel Persistence
2:34 Centreon Statement and Impact
3:10 Start of Sandworm Demo
3:19 Chain Prerequisites
4:37 Chain Rundown
6:31 Chain Deploy
7:33 Outro