Orangeworm is a threat actor targeting healthcare with the Kwampirs backdoor.
Analyst brief
Orangeworm is a threat actor first identified in 2015, targeting the healthcare sector across the US, Europe, and Asia. The group uses a custom backdoor named 'Kwampirs' to conduct corporate espionage against healthcare providers, pharmaceutical companies, and IT solution providers as part of supply-chain attacks. Their key TTPs involve lateral movement via SMB/Windows Admin Shares (T1021.002), command and control using Web Protocols (T1071.001), and reconnaissance with standard system utilities like netstat and systeminfo. Defenders should monitor SMB traffic, unauthorized admin share access, and indicators of compromise (IOCs) for the Kwampirs backdoor, especially within healthcare and related industries.
Orangeworm
unknown
Symantec has identified a previously unknown group called Orangeworm that has been observed installing a custom backdoor called Trojan.Kwampirs within large international corporations that operate within the healthcare sector in the United States, Europe, and Asia.
First identified in January 2015, Orangeworm has also conducted targeted attacks against organizations in related industries as part of a larger supply-chain attack in order to reach their intended victims. Known victims include healthcare providers, pharmaceuticals, IT solution providers for healthcare and equipment manufacturers that serve the healthcare industry, likely for the purpose of corporate espionage.
Monitor network traffic for suspicious web protocol activity and implement network segmentation.
FAQ2
What specific malware does the Orangeworm group use?+
The Orangeworm group primarily uses a custom backdoor called "Kwampirs" (Trojan.Kwampirs).
What sector does Orangeworm primarily target?+
Orangeworm primarily targets the healthcare sector, including healthcare providers, pharmaceutical companies, and IT solution providers in their supply chain.