The FBI warned that attackers are conducting an ongoing campaign against software supply chain companies using the Kwampirs remote access trojan, compromising providers in order to reach their partners and customers. The alert said the activity affects organizations tied to industrial control systems supporting global energy generation, transmission, and distribution, and that victims have also been identified in the healthcare, energy, and financial sectors.
The campaign appears to expand on earlier reporting that linked Kwampirs and the Orangeworm group primarily to healthcare-focused supply chain intrusions. The FBI said code analysis found multiple similarities between Kwampirs and Shamoon/Disttrack, malware associated with the Iranian-linked APT33 group, while noting that Kwampirs itself has not been observed carrying a wiper component.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
On 2020-03-30, the FBI issued another Private Industry Notification on the Kwampirs campaign, saying it was the bureau's third alert on the group in 2020. The bureau also re-released related Flash alerts with additional information, including YARA rules, a technical report, and indicators of compromise.
In April 2019, Lab52 published a report that confirmed Symantec's earlier findings and the group's focus on the healthcare sector.
In April 2018, Symantec first publicly described the Kwampirs malware and reported that the Orangeworm group was targeting healthcare-related supply chain companies. Symantec assessed the campaign was primarily focused on healthcare, with secondary targeting of linked industries.
Symantec said the Orangeworm group had been operating since 2015, using the Kwampirs remote access trojan in its intrusion activity.
In its alert, the FBI provided indicators of compromise and YARA rules for Kwampirs and said new code analysis found numerous similarities between Kwampirs and Shamoon/Disttrack. The bureau noted that Kwampirs had not been observed with a wiper component.
The FBI said recent Kwampirs attacks had evolved beyond the earlier healthcare-focused activity to target companies in the industrial control systems sector, especially energy. It also said Kwampirs had been deployed against healthcare, energy, and financial sector organizations.
The FBI issued a security alert to the US private sector about an ongoing campaign using Kwampirs to target software supply chain providers in order to reach downstream partners and customers. The alert said downstream targets included organizations supporting industrial control systems for global energy generation, transmission, and distribution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
blog.reversinglabs.com
Open sourcezdnet.com
Open sourcezdnet.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourcesymantec.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.