Orangeworm is a threat group known for targeted intrusions against the healthcare sector and adjacent parts of the healthcare supply chain. The group has been active since at least 2015 and is best known for deploying the Kwampirs backdoor to obtain remote access inside victim environments. Confirmed victimology has included healthcare providers, pharmaceutical organizations, healthcare IT solution providers, equipment manufacturers, and other organizations whose products or services support healthcare operations. Activity has been observed against large international organizations in the United States, Europe, and Asia, with the United States representing the largest reported regional concentration of victims. Orangeworm’s operations have been characterized as supply-chain-oriented targeting intended to reach downstream healthcare victims through related industries. Reported secondary targeting has included manufacturing, information technology, logistics, and agriculture where those entities had direct links to medical device production, clinic IT support, or healthcare product delivery. Infections have been identified on systems associated with medical imaging and patient workflow environments, including systems used with imaging devices and patient consent processes. Kwampirs provides remote access and performs host and network discovery by collecting system version, language, network adapter, share, mapped drive, and recently accessed system information. The malware establishes persistence as a Windows service and has been observed modifying its decrypted payload with randomized content before writing it to disk in order to evade hash-based detection. Orangeworm has also used HTTP for command-and-control communications. After identifying systems of interest, the group has spread aggressively through open network shares, including administrative shares, to infect additional hosts within compromised environments. The campaign has widely been assessed as espionage-oriented, specifically corporate espionage, rather than financially motivated or destructive. Early public assessments noted an absence of clear technical or operational hallmarks of a nation-state actor. Later research reported code and behavioral overlaps between Kwampirs and Shamoon, raising the possibility of a closer relationship to Iranian state-linked activity, but that linkage remains an assessment rather than settled attribution. High-confidence reporting therefore supports Orangeworm as an espionage-focused intrusion set associated with Kwampirs, without definitive state attribution.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an associated analytic story; no specific activity by the group is described in this reference.
Mentioned only in passing as an associated analytic story, not discussed as the subject of the reference.
Mentioned only as an associated analytic story in a deprecated Splunk detection entry; no actor activity is described in this reference.
Orangeworm Attack Group
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.