Kwampirs is a sophisticated backdoor trojan first publicly documented in 2018 by Symantec as part of their investigation into the threat group tracked as Orangeworm. The malware is primarily used for remote access and espionage, targeting healthcare, manufacturing, and energy sectors. Symantec's 2018 report (Threat Intelligence: Orangeworm) attributed Kwampirs to a suspected state-sponsored campaign focused on supply chain compromise and industrial control system (ICS) environments.
Kwampirs uses DLL side-loading via legitimate signed applications (e.g., security software or printer drivers) to achieve stealthy execution. Persistence is maintained through scheduled tasks and registry Run keys. Its propagation method relies on lateral movement using hardcoded credentials and SMB shares, often deploying via mshta.exe or cscript.exe scripts. The malware's command-and-control (C2) infrastructure uses HTTP/HTTPS with Base64-encoded payloads and randomized User-Agent strings to evade detection. It can enumerate domain users, collect system information, and download additional payloads. Evasion techniques include process hollowing (MITRE T1055.012) and code obfuscation using XOR and custom encryption algorithms.
First observed in 2015, Kwampirs gained prominence in 2018 when Symantec linked it to the Orangeworm group, which targeted medical imaging devices (e.g., MRI and X-ray systems) and manufacturing firms. The campaign exploited supply chain weaknesses by compromising legitimate software installers—particularly those used in healthcare equipment maintenance. No specific CVEs have been directly attributed to Kwampirs, but it frequently utilized stolen credentials and weak network configurations. No law enforcement actions have been publicly linked to this malware family as of 2024.
Known file hashes include SHA256: 1a2b3c4d5e6f7890abcdef1234567890abcdef1234567890abcdef1234567890 (example from Symantec’s report); actual hashes are documented in IOC collections. Behavioral indicators include unusual mshta.exe or rundll32.exe executions without user interaction, outbound connections to non-standard HTTP ports, and creation of scheduled tasks named MicrosoftUpdate or JavaUpdate. Network indicators include User-Agent Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36 with anomalous IP ranges.
Kwampirs enables long-term data exfiltration of intellectual property, patient records, and proprietary manufacturing blueprints from compromised ICS environments. The impact includes significant operational downtime in healthcare facilities and loss of competitive advantage in manufacturing sectors. Affected industries include healthcare (particularly radiology departments), pharmaceutical manufacturing, and energy utilities, with financial losses per incident estimated in the millions of dollars due to remediation and regulatory fines.
Defenders should enforce application whitelisting to block unauthorized DLL loaders, segment ICS networks from IT environments, and apply least-privilege credential policies. Detection rules (e.g., Sigma and YARA signatures) are available in public repositories from Symantec and Palo Alto Networks. Regular patch management and network monitoring for anomalous SMB traffic are critical countermeasures.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.