Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
2
techniques
8
software
9,273
corpus matches
profile
Orangeworm is a group that has targeted organizations in the healthcare sector in the United States, Europe, and Asia since at least 2015, likely for the purpose of corporate espionage. Reverse engineering of Kwampirs, directly associated with Orangeworm activity, indicates significant functional and development overlaps with Shamoon.
techniques
2 attributed · most-instrumented first
software
8 malware & tools attributed
Net
S0039
Systeminfo
S0096
Arp
S0099
ipconfig
S0100
route
S0103
netstat
S0104
cmd
S0106
Kwampirs
S0236
read this carefully
9,273 corpus matches is not attribution
That count is indicators which exhibit techniques Orangeworm is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
showing 30 of 9,273