Kwampirs
MITRE ATT&CK: S0236 View on attack.mitre.org
Aliases: Kwampirs
- Malware type
- backdoor, trojan
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:53:34
Targeted industries: healthcare-and-pharmaceutical
Context
Kwampirs is a backdoor Trojan used by Orangeworm. Kwampirs has been found on machines which had software installed for the use and control of high-tech imaging devices such as X-Ray and MRI machines. Kwampirs has multiple technical overlaps with Shamoon based on reverse engineering analysis.
Detection coverage
- 4 YARA rules
- 371 Sigma rules
Malware & tools used
- Domain Groups (attack-pattern)
- Local Account (attack-pattern)
- Network Share Discovery (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- System Service Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Windows Service (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Remote System Discovery (attack-pattern)
- SMB/Windows Admin Shares (attack-pattern)
- Binary Padding (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- System Information Discovery (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Rundll32 (attack-pattern)
- Process Discovery (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Password Policy Discovery (attack-pattern)
- Fallback Channels (attack-pattern)
- Local Groups (attack-pattern)
Used by threat actors
- Orangeworm (threat-actor)
Detection rules
- CRAIU_Apt_ZZ_Orangeworm_Kwampirs_Shamoon_Code (yara-rule)
- CRAIU_Apt_ZZ_Orangeworm_Kwampirs_Installer (yara-rule)
- CRAIU_Apt_ZZ_Orangeworm_Kwampirs_Implant (yara-rule)
- MALPEDIA_Win_Kwampirs_Auto (yara-rule)
Reports & references
- Broadcom/Symantec — Orangeworm Targets Healthcare Us Europe Asia (report)
- resources.cylera.com — Cylera%20Labs%20Kwampirs%20Shamoon%20Technical%20Report (report)
- blackberry.com — Report Bb 2021 Threat Report (report)
- zdnet.com — Fbi Warns About Ongoing Attacks Against Software Supply Chain Companies (report)
- atlanticcouncil.org — Breaking Trust Shades Of Crisis Across An Insecure Software Supply Chain (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Kwampirs (report)
- securityartwork.es — Orangeworm Group Kwampirs Analysis Update (report)
- resources.cylera.com — New Evidence Linking Kwampirs Malware To Shamoon Apts (report)
- zdnet.com — Fbi Re Sends Alert About Supply Chain Attacks For The Third Time In Three Months (report)
- thehackernews.com — Researchers Find New Evidence Linking (report)
- documentcloud.org — 6821581 Flash Cp 000111 Mw Downgraded Version (report)
- blog.reversinglabs.com — Unpacking Kwampirs Rat (report)
- MITRE ATT&CK — S0236 (report)