NEW: Group Profiler — instant APT intel lookup. Try it →

Orangeworm

Overview

Orangeworm is a group that has targeted organizations in the healthcare sector in the United States, Europe, and Asia since at least 2015, likely for the purpose of corporate espionage. Reverse engineering of Kwampirs, directly associated with Orangeworm activity, indicates significant functional and development overlaps with Shamoon.

Naming & attribution

Orangeworm is tracked under 1 names across the industry. It uses 2 documented ATT&CK techniques — more than 5% of the 174 groups tracked here. Activity attributed since at least 2015.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
OrangewormSymantec Security Response Attack Investigation Team

TTPs — 2 techniques across 2 tactics

Lateral Movement

Command and Control

Tools & malware (8)

Kwampirs · netstat · Net · ipconfig · cmd · route · Arp · Systeminfo

Reporting (2)