Uptime Hamster: 29d 21h 28mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Orangeworm

Orangeworm

1 incidentes 1 paises 1 sectores apt null Ultimo: 2026-05-25
Aliases: Kwampirs backdoor, empresas farmacéuticas, proveedores de soluciones IT para el sector sanitario, fabricantes de equipos médicos
Ver en IntelTracker → APTTrail →
Orangeworm is a cyber espionage threat actor group that emerged in January 2015, primarily targeting the healthcare sector in the United States, Europe, and Asia through carefully planned supply-chain attacks. The group is assessed with unknown confidence to be composed of an individual or a small group, as there are no technical or operational indicators to suggest state sponsorship. Their main motivation is corporate espionage, likely involving the theft of medical organization patents and intellectual property for resale. A distinctive characteristic of Orangeworm is its aggressive use of custom backdoor malware, known as Kwampirs, which has been found on critical medical infrastructure such as X-ray and MRI machines, as well as patient consent systems. Despite the malware's 'noisy' propagation methods across networks, the group appears unconcerned with detection.

Aliases del actor

Kwampirs backdoorempresas farmacéuticasproveedores de soluciones IT para el sector sanitariofabricantes de equipos médicos

Actores similares

backdoordiplomacyactor · 2capi-backdooractor · 1apt-sectora05actor · 1BackdoorDiplomacyapt · 1private-sector-offensiveactor · 1
Motivacion