CMS8000 Backdoor

Malware type
backdoor
Last IoC activity
2026-07-06 12:39:27
Profile updated
2026-07-07 14:23:45

Targeted industries: healthcare-and-pharmaceutical

Context

According to CISA, this is an implant found in firmware for the Contec CMS8000, a patient monitor used by the Healthcare and Public Health sector. An embedded backdoor function with a hard-coded IP address and functionality that enables patient data spillage was identified.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.Cms8000 Backdoor (report)
  • CISA — Fact Sheet Contec Cms8000 Contains A Backdoor 508C (report)
  • claroty.com — Are Contec Cms8000 Patient Monitors Infected With A Chinese Backdoor The Reality Is More Complicated (report)

External references