Kwampirs

MITRE ATT&CK: S0236 View on attack.mitre.org

Aliases: Kwampirs

Malware type
backdoor, trojan
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:53:34

Targeted industries: healthcare-and-pharmaceutical

Context

Kwampirs is a backdoor Trojan used by Orangeworm. Kwampirs has been found on machines which had software installed for the use and control of high-tech imaging devices such as X-Ray and MRI machines. Kwampirs has multiple technical overlaps with Shamoon based on reverse engineering analysis.

Detection coverage

  • 4 YARA rules
  • 371 Sigma rules

Malware & tools used

  • Domain Groups (attack-pattern)
  • Local Account (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • System Service Discovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Windows Service (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • Binary Padding (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Rundll32 (attack-pattern)
  • Process Discovery (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Password Policy Discovery (attack-pattern)
  • Fallback Channels (attack-pattern)
  • Local Groups (attack-pattern)

Used by threat actors

Detection rules

  • CRAIU_Apt_ZZ_Orangeworm_Kwampirs_Shamoon_Code (yara-rule)
  • CRAIU_Apt_ZZ_Orangeworm_Kwampirs_Installer (yara-rule)
  • CRAIU_Apt_ZZ_Orangeworm_Kwampirs_Implant (yara-rule)
  • MALPEDIA_Win_Kwampirs_Auto (yara-rule)

Reports & references

  • Broadcom/Symantec — Orangeworm Targets Healthcare Us Europe Asia (report)
  • resources.cylera.com — Cylera%20Labs%20Kwampirs%20Shamoon%20Technical%20Report (report)
  • blackberry.com — Report Bb 2021 Threat Report (report)
  • zdnet.com — Fbi Warns About Ongoing Attacks Against Software Supply Chain Companies (report)
  • atlanticcouncil.org — Breaking Trust Shades Of Crisis Across An Insecure Software Supply Chain (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Kwampirs (report)
  • securityartwork.es — Orangeworm Group Kwampirs Analysis Update (report)
  • resources.cylera.com — New Evidence Linking Kwampirs Malware To Shamoon Apts (report)
  • zdnet.com — Fbi Re Sends Alert About Supply Chain Attacks For The Third Time In Three Months (report)
  • thehackernews.com — Researchers Find New Evidence Linking (report)
  • documentcloud.org — 6821581 Flash Cp 000111 Mw Downgraded Version (report)
  • blog.reversinglabs.com — Unpacking Kwampirs Rat (report)
  • MITRE ATT&CK — S0236 (report)

External references