French agency ANSSI attributes a series of attacks targeting Centreon servers to the Russia-linked Sandworm APT group. The group is also the author of the NotPetya ransomware that hit hundreds of companies worldwide in June 2017, causing billions worth of damage. Sandworm (aka BlackEnergy and TeleBots) has been active since 2000, it operates under the control of Unit 74455 of the Russian GRUs Main Center for Special Technologies (GTsST)”]
Source: https://securityaffairs.co/wordpress/114606/apt/anssi-sandworm-hosting-providers-attacks.html

