Kwampirs

S0236

Malware.View on attack.mitre.org

About this malware

Kwampirs is a backdoor Trojan used by Orangeworm. Kwampirs has been found on machines which had software installed for the use and control of high-tech imaging devices such as X-Ray and MRI machines. Kwampirs has multiple technical overlaps with Shamoon based on reverse engineering analysis.

Techniques used22

Procedure examples22

TechniqueProcedure example
T1007
System Service Discovery

Kwampirs collects a list of running services with the command tasklist /svc.

T1008
Fallback Channels

Kwampirs uses a large list of C2 servers that it cycles through until a successful connection is established.

T1016
System Network Configuration Discovery

Kwampirs collects network adapter and interface information by using the commands ipconfig /all, arp -a and route print. It also collects the system's MAC address with getmac and domain configuration with net config workstation.

T1018
Remote System Discovery

Kwampirs collects a list of available servers with the command net view.

T1021.002
SMB/Windows Admin Shares

Kwampirs copies itself over network shares to move laterally on a victim network.

T1027.001
Binary Padding

Before writing to disk, Kwampirs inserts a randomly generated string into the middle of the decrypted payload in an attempt to evade hash-based detections.

T1027.013
Encrypted/Encoded File

Kwampirs downloads additional files that are base64-encoded and encrypted with another cipher.

T1033
System Owner/User Discovery

Kwampirs collects registered owner details by using the commands systeminfo and net config workstation.

T1036.004
Masquerade Task or Service

Kwampirs establishes persistence by adding a new service with the display name "WMI Performance Adapter Extension" in an attempt to masquerade as a legitimate WMI service.

T1049
System Network Connections Discovery

Kwampirs collects a list of active and listening connections by using the command netstat -nao as well as a list of available network mappings with net use.

T1057
Process Discovery

Kwampirs collects a list of running services with the command tasklist /v.

T1069.001
Local Groups

Kwampirs collects a list of users belonging to the local users and administrators groups with the commands net localgroup administrators and net localgroup users.

T1069.002
Domain Groups

Kwampirs collects a list of domain groups with the command net localgroup /domain.

T1082
System Information Discovery

Kwampirs collects OS version information such as registered owner details, manufacturer details, processor type, available storage, installed patches, hostname, version info, system date, and other system information by using the commands systeminfo, net config workstation, hostname, ver, set, and date /t.

T1083
File and Directory Discovery

Kwampirs collects a list of files and directories in C:\ with the command dir /s /a c:\ >> "C:\windows\TEMP\[RANDOM].tmp".

View all 22 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. Cylera Kwampirs 2022 Open source
    Pablo Rincón Crespo. (2022, January). The link between Kwampirs (Orangeworm) and Shamoon APTs. Retrieved February 8, 2024.
  2. Symantec Orangeworm April 2018 Open source
    Symantec Security Response Attack Investigation Team. (2018, April 23). New Orangeworm attack group targets the healthcare sector in the U.S., Europe, and Asia. Retrieved May 8, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.