Orangeworm

MITRE ATT&CK: G0071 View on attack.mitre.org

Aliases: Orangeworm

First seen
2015-01-01 00:00:00
Primary motivation
espionage
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Related IoCs
5 (4 malicious)
Last IoC activity
2026-06-28 15:16:43
Profile updated
2026-07-07 11:54:48

Targeted industries: healthcare-and-pharmaceutical

Targeted regions: country_code:us country_code:de country_code:cn

Context

Orangeworm is a group that has targeted organizations in the healthcare sector in the United States, Europe, and Asia since at least 2015, likely for the purpose of corporate espionage. Reverse engineering of Kwampirs, directly associated with Orangeworm activity, indicates significant functional and development overlaps with Shamoon.

Recent IoC activity

4 malicious indicators in Maltiverse are attributed to Orangeworm (G0071). The 4 most recently updated:

TypeIndicatorUpdatedSources
hostname ncdndswjfnsite.com 2026-06-28 1
hostname servncdnservnrj.info 2026-06-27 1
hostname www.dswsite.nl 2026-06-15 1
hostname powerserv.nl 2026-03-05 1

Detection coverage

  • 6 YARA rules
  • 67 Sigma rules

Malware & tools used

Reports & references

  • Broadcom/Symantec — Orangeworm Targets Healthcare Us Europe Asia (report)
  • MITRE ATT&CK — G0071 (report)
  • resources.cylera.com — Cylera%20Labs%20Kwampirs%20Shamoon%20Technical%20Report (report)

External references