logo

New Orangeworm attack group targets the healthcare sector in the U.S., Europe, and Asia | Symantec Blogs

ID: 0d9f7e2a-ebaa-4b16-b3cc-8fc262bcd0a6

STIX ID: report--0d9f7e2a-ebaa-4b16-b3cc-8fc262bcd0a6

Threat Score

70/100

Uploaded: 2026-08-19

Published Date: 2018-04-25

Last Modified Date: 2018-04-25

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec reports on Orangeworm, a previously undocumented threat group deploying the custom Kwampirs backdoor primarily against healthcare organizations and related supply-chain partners across multiple countries; Kwampirs persists by creating a Windows service, propagates aggressively via network shares (including legacy systems), collects system/network reconnaissance data, and beacons to an embedded C2 list, while Symantec provides detections, IOCs, and guidance to protected customers.