ATT&CKGroupsOrangeworm

Orangeworm

G0071

Threat group.View on attack.mitre.org

About this group

Orangeworm is a group that has targeted organizations in the healthcare sector in the United States, Europe, and Asia since at least 2015, likely for the purpose of corporate espionage. Reverse engineering of Kwampirs, directly associated with Orangeworm activity, indicates significant functional and development overlaps with Shamoon.

Techniques used2

Procedure examples2

TechniqueProcedure example
T1021.002
SMB/Windows Admin Shares

Orangeworm has copied its backdoor across open network shares, including ADMIN$, C$WINDOWS, D$WINDOWS, and E$WINDOWS.

T1071.001
Web Protocols

Orangeworm has used HTTP for C2.

Software8

Campaigns0

None recorded.

References2

  1. Cylera Kwampirs 2022 Open source
    Pablo Rincón Crespo. (2022, January). The link between Kwampirs (Orangeworm) and Shamoon APTs. Retrieved February 8, 2024.
  2. Symantec Orangeworm April 2018 Open source
    Symantec Security Response Attack Investigation Team. (2018, April 23). New Orangeworm attack group targets the healthcare sector in the U.S., Europe, and Asia. Retrieved May 8, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.