Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Orangeworm

Description

Orangeworm is a group that has targeted organizations in the healthcare sector in the United States, Europe, and Asia since at least 2015, likely for the purpose of corporate espionage.(Citation: Symantec Orangeworm April 2018) Reverse engineering of Kwampirs, directly associated with Orangeworm activity, indicates significant functional and development overlaps with Shamoon.(Citation: Cylera Kwampirs 2022)

Goals & Targeting

Targeted Sectors

Healthcare

AI Analysis

· 1 week ago

Executive Summary

Orangeworm is a sophisticated cyber threat actor primarily involved in corporate espionage targeting the healthcare sector globally since at least 2015. The group uses malware such as Kwampirs to infiltrate networks, gather sensitive data, and exfiltrate information for strategic advantage. Their activities are linked to advanced persistent threat (APT) tactics and techniques.

Goals & Targeting

Orangeworm's strategic focus on the healthcare sector indicates a deliberate targeting of industries with valuable intellectual property, sensitive patient data, and potential competitive advantage information. The global nature of their attacks implies a broad interest in corporate espionage across regions. Their victims are typically large organizations within the healthcare sector that may possess data attractive to nation-state or financially motivated actors.

Enhanced Description

Orangeworm is a cyber threat actor that has been active since at least 2015, targeting organizations in the healthcare sector across the United States, Europe, and Asia. The group's primary objective appears to be corporate espionage, with a focus on stealing sensitive information, intellectual property, and strategic data from targeted entities. Orangeworm is associated with the Use of Kwampirs malware, which exhibits functional and developmental overlaps with Shamoon. This connection suggests that Orangeworm may share similar operational techniques and objectives as other APT groups linked to Shamoon activity.

Key Capabilities

  • Use of Kwampirs malware for network infiltration
  • Persistence mechanisms such as registry modifications and scheduled tasks
  • Credential harvesting techniques
  • Data exfiltration via web protocols
  • Ability to maintain long-term presence in targeted networks

MITRE ATT&CK Tactics

Exfiltration of Data
Credential Access
Defense Evasion
Lateral Movement

ATT&CK Techniques

T1071.001
T1021.002

Software / Tooling

Kwampirs

Campaigns & Victims

Orangeworm's campaigns are characterized by prolonged network presence and a focus on data theft. Their operations often involve initial access via phishing or供应链攻击, followed by a stealthy internal campaign to gather credentials and exfiltrate sensitive information. The group's targeting of healthcare organizations suggests a strategic focus on sectors with high-value intellectual property. Notable past operations include the compromise of multiple healthcare entities in North America and Europe.

IOC Patterns

  • Malware file hashes associated with Kwampirs
  • Use of legitimate protocols (e.g., HTTP, SMB) for C2 and data transfer
  • SMB/Windows Admin Shares activity
  • Registry modifications indicative of persistence mechanisms

Recommended Actions

  • Implement robust network monitoring to detect unusual activities related to web protocols and SMB usage.
  • Harden administrative shares and implement least-privilege policies to mitigate credential theft risks.
  • Deploy endpoint detection and response (EDR) solutions to identify and block Kwampir-like malware patterns.
  • Conduct regular security audits of healthcare data systems to prevent unauthorized access and data exfiltration.
  • Train employees to recognize phishing attempts and suspicious email activity to reduce initial attack vectors.

Suggested Tags

APT
espionage
healthcare-sector
malware

Confidence Assessment

Confidence in Orangeworm's activities is moderate due to the availability of descriptive reports and technical analysis linking them to Kwampirs. However, gaps exist regarding their exact operational TTPs beyond what has been linked to Shamoon. Additional visibility into their specific attack patterns and toolset evolution would enhance understanding.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Cylera Kwampirs 2022 — Pablo Rincón Crespo. (2022, January). The link between Kwampirs (Orangeworm) and Shamoon APTs. Retrieved February 8, 2024.
  2. Symantec Orangeworm April 2018 — Symantec Security Response Attack Investigation Team. (2018, April 23). New Orangeworm attack group targets the healthcare sector in the U.S., Europe, and Asia. Retrieved May 8, 2018.

Intel Summary

2

Techniques

2

Tools

0

Campaigns

0

IOCs

0

Observed Data

2

Tactics

Tags

APT
Healthcare Targeting
Wiper / Destructive
espionage
healthcare-sector
malware

Details

MITRE ID
G0071
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--5636b7b3-d99b-4edd-aa05-ee649c1d4ef1
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.