Orangeworm is a threat group first identified in 2015 that conducted corporate-espionage-oriented intrusions against large healthcare organizations and their supply chains. The group is associated with the Kwampirs remote-access backdoor. Its primary targets include healthcare providers, pharmaceutical organizations, healthcare IT providers, and manufacturers supporting medical-device environments; infections have affected systems associated with medical imaging and patient-consent workflows. Orangeworm has also targeted related supply-chain organizations, including logistics and other technology suppliers. Kwampirs provides remote access, collects host, network-adapter, operating-system, and language information, and enumerates network resources and files. It establishes persistence through a Windows service and propagates aggressively through accessible network and administrative shares after identifying systems of interest. The malware uses HTTP-based command-and-control communications and can cycle through embedded command-and-control infrastructure. It modifies its decrypted payload with randomly generated data before writing it to disk, frustrating hash-based detection. Orangeworm activity has been observed against international organizations in the United States, Europe, and Asia. Its country of origin has not been established with high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed in the detection's Annotations section.
Mentioned only as an associated analytic story; no specific activity by the group is described in this reference.
Mentioned only in passing as an associated analytic story, not discussed as the subject of the reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.