Orangeworm

MISP
Tipo:
Unknown
Paese:
Unknown
Prima attivita:
Unknown
Dettagli:

Symantec has identified a previously unknown group called Orangeworm that has been observed installing a custom backdoor called Trojan.Kwampirs within large international corporations that operate within the healthcare sector in the United States, Europe, and Asia.
First identified in January 2015, Orangeworm has also conducted targeted attacks against organizations in related industries as part of a larger supply-chain attack in order to reach their intended victims. Known victims include healthcare providers, pharmaceuticals, IT solution providers for healthcare and equipment manufacturers that serve the healthcare industry, likely for the purpose of corporate espionage.

MITRE ATT&CK: View on MITRE
Tecniche Utilizzate (2)
ID ATT&CK Tattiche
T1021.002 SMB/Windows Admin Shares -
T1071.001 Web Protocols -
Metadata
ID: 163
Created: 13/01/2026 17:48
Updated: 07/03/2026 04:00