New Orangeworm attack group targets the healthcare sector in the U.S., Europe, and Asia | Symantec Blogs
ID: 0d9f7e2a-ebaa-4b16-b3cc-8fc262bcd0a6
STIX ID: report--0d9f7e2a-ebaa-4b16-b3cc-8fc262bcd0a6
Threat Score
70/100
Uploaded: 2026-08-19
Published Date: 2018-04-25
Last Modified Date: 2018-04-25
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec reports on Orangeworm, a previously undocumented threat group deploying the custom Kwampirs backdoor primarily against healthcare organizations and related supply-chain partners across multiple countries; Kwampirs persists by creating a Windows service, propagates aggressively via network shares (including legacy systems), collects system/network reconnaissance data, and beacons to an embedded C2 list, while Symantec provides detections, IOCs, and guidance to protected customers.
