Kwampirs is a Windows remote access backdoor associated primarily with the Orangeworm intrusion set. It has been used in long-running supply-chain-oriented campaigns that heavily targeted healthcare organizations and related industries, including healthcare IT providers, medical equipment manufacturers, pharmaceuticals, logistics, software suppliers, and later organizations in energy, engineering, and financial sectors. Infections have been observed across the United States, Europe, Asia, and the Middle East, including systems associated with medical imaging and hospital operational environments.
After execution, Kwampirs decrypts and extracts its main DLL payload from embedded resources and has been observed modifying the payload with randomly generated data to evade hash-based detection. It establishes persistence on Windows systems by creating or configuring services and by using rundll32.exe to load its DLL payload. The malware provides remote access to operators and maintains command-and-control resilience by cycling through a large embedded list of servers until communication succeeds.
Kwampirs performs extensive host and network reconnaissance. Documented behaviors include enumerating running services and processes, collecting system and registered-owner information, gathering network adapter, routing, ARP, MAC address, and domain configuration details, identifying available servers, and enumerating local and remote network shares and domain groups. Once operators identify systems of interest, Kwampirs can spread laterally by copying itself across open or hidden administrative network shares, enabling compromises ranging from a small number of hosts to broad enterprise-wide infections.
Multiple public assessments have linked Kwampirs activity to supply-chain compromise and corporate espionage objectives. Separate research and government reporting have noted code and behavioral similarities between Kwampirs and Shamoon/DistTrack, raising the possibility of shared development lineage or closely related operators, though Kwampirs itself has not been publicly documented as having a destructive wiper component.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Symantec has identified a previously unknown group called Orangeworm that has been observed installing a custom backdoor called Trojan.Kwampirs within large international corporations that operate within the healthcare sector... Once Orangeworm has infiltrated a victim’s network, they deploy Trojan.Kwampirs, a backdoor Trojan that provides the attackers with remote access to the compromised computer.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The FBI has sent a security alert to the US private sector about an ongoing hacking campaign that's targeting supply chain software providers... 'Software supply chain companies are believed to be targeted in order to gain access to the victim's strategic partners and/or customers, including entities supporting Industrial Control Systems (ICS) for global energy generation, transmission, and distribution,'
download additional payloads to execute from their C2 servers
Examples include "admin@338 actors used the following commands ... dir c:\ >> %temp%\download", "BabyShark has used dir to search for 'programfiles' and 'appdata'", and "FIN13 has used the Windows dir command to enumerate files and directories in a victim's network."
This technique is not novel. It has been employed in various forms for several years to achieve different effects, all of which are related to evading defense mechanisms.
Binary padding is the process of adding extra or junk data to a portable executable (PE) file that, while not changing the behavior of the binary, changes certain characteristics that can help with either obfuscating relevant code or defeating sandboxing solutions and detections.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
During the 2015 Ukraine Electric Power Attack, Sandworm Team remotely discovered systems over LAN connections. OT systems were visible from the IT network as well, giving adversaries the ability to discover operational assets.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information. | Multiple entries explicitly state use of the Windows systeminfo command, e.g., 'BlackEnergy has used Systeminfo to gather the OS version...' and 'OilRig has run hostname and systeminfo on a victim.'
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
Numerous entries mention enumerating drives, logical disks, disk type, free space, or volume information; examples include 'Babuk can enumerate disk volumes,' 'Cuba can enumerate local drives,' and 'TAINTEDSCRIBE can use DriveList to retrieve drive information.'
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
the use of the same InternetOpenW Windows API to craft HTTP requests to the command-and-control (C2) server
43 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Kwampirs is described as a backdoor used to change file hashes by inserting a randomly generated string into the binary, helping evade hash-based detections.
Worm/backdoor malware that collects a list of network shares using net share.
Backdoor/worm that collects registered owner details using systeminfo and net config workstation.
Collects extensive network adapter, interface, ARP, routing, MAC, and domain configuration information.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.