French cybersecurity agency warns of intrusion campaign targeting Centreon ANSSI, the French cybersecurity agency, has reported an intrusion campaign targeting the monitoring software Centreon distributed by the French company CENTREON which resulted in the breach of several French entities. The first victim seems to have been compromised from late 2017. The campaign lasted until 2020. This campaign mostly affected information technology providers, especially web hosting providers. On compromised systems, ANSSI discovered the presence of a backdoor in the form of a webshell dropped on several Centreon servers exposed to the internet. This backdoor was identified as being the P.A.S. webshell, version number 3.1.4. On the same servers, ANSSI found another backdoor identical to one described by ESET and named Exaramel. This campaign bears several similarities with previous campaigns attributed to the intrusion set named Sandworm. "Generally speaking, the intrusion set Sandworm is known to lead consequent intrusion campaigns before focusing on specific targets that fits its strategic interests within the victims pool. The campaign observed by ANSSI fits this behavior." In a report , ANSSI provides recommendations and detection methods, as well as technical information detailing this campaign: targeted systems, detailed malwares code analysis, infrastructure, tactics, techniques, and procedures and link with the intrusion set Sandworm.  According to Bloomberg , a spokesman for the Russian government, Dmitry Peskov, says suggestions that the attack was connected to Russia are "absurd. Russia did not have, does not have and cannot have any involvement in any cybercrime." On its website, Centreon lists customers such as Airbus, Agence France Press, Euronews, Orange, Lacoste, Sephora, ArcelorMittal, Total, SoftBank, Air France a knockout post KLM, and several French government agencies and city governments.  The French company confirmed the hack later on, saying no Centreon customers were impacted. "According to discussions over the past 24 hours with ANSSI, only about fifteen entities were the target of this campaign, and that they are all users of an obsolete open source version (v2.5.2), which has been unsupported for 5 years." Brandon Hoffman, Chief Information Security Officer at Netenrich , a San Jose, Calif.-based provider of IT, cloud, and cybersecurity operations and services, says, "The targeting of Centreon software as an intrusion point into organizations feels very much like the SolarWinds issue of late. Tying this back to Russia also provides strong correlation that third party software vendors have been a primary attack vector for Russian agencies spanning the past couple of years. The fact that both of these attacks, SolarWinds and Centreon went undetected for so long speaks to the importance of strengthening third party security concerns as well as deeper reviews of detection measures. In both cases there was re-use of malware that was previously known. Meaning even if the initial vector was novel, at some point the detection tools and methodologies should have picked something up, especially over YEARS of adversaries being resident on systems." Oleg Kolesnikov, VP of Threat Research at Securonix , on the other hand, says, "It's tempting to compare the Centreon and SolarWinds attacks since both are similar in functionality, but Centreon seems to be a victim of internet-exposed systems rather than a supply chain breach.


