Saturday, November 2, 2024
HomeCyber AttackAPT Group Cyber Attack Against Medical Sectors to Hack X-Ray & MRI...

APT Group Cyber Attack Against Medical Sectors to Hack X-Ray & MRI Scan Machines

Published on

Malware protection

New APT Cyber espionage group Orangeworm targeting healthcare sectors and other medical related industries to deploy the powerful Kwampirs backdoor to compromise the medical devices such as X-Ray & MRI Scan Machines.

Kwampirs backdoor initially discovered in 2016 that can able to open a potential backdoor in compromised computers to steal the sensitive information and also download malicious files.

The orangeworm APT cyber group mainly targeting healthcare sector in the U.S., Europe, Asia and they are active since 2015.

- Advertisement - SIEM as a Service

Apart From Healthcare industries, Orangeworm APT also targeting the related industries such as healthcare providers, pharmaceuticals, IT solution providers for healthcare and equipment manufacturers that serve the healthcare industry.

This is one of the well-planned attack against the medical industries with a good amount of planning before they attack the specific industries.

Orangeworm high amount of attack registered against Healthcare industries and other related industries also infected followed by Healthcare.

According to Symantec, We believe that these industries have also been targeted as part of a larger supply-chain attack in order for Orangeworm to get access to their intended victims related to healthcare. Orangeworm’s secondary targets include Manufacturing, Information Technology, Agriculture, and Logistics.

Also Read:  Best Ways to Prepare Your Organization For Cyber Disasters

Orangeworm Attack Against X-Ray and MRI Machines 

Kwampirs backdoor discovered within the software that used to control the medical equipment such as  X-Ray and MRI machines and also Orangeworm was recognized to have an interest in machines used to assist patients.

The biggest amount of victims have been identified in the U.S with 17 percent of the infection and India, Saudi Arabia, Philippines etc countries are severely affected next to the U.S.

Initial infection leads to compromise the network and deploy the Kwampirs backdoor that takes a remote control of the victim’s machine.

During the infection, it using randomly generated string to decrypt the payload to evade the signature-based detection.

Also, it performs various tasks to maintin its persistence and this backdoor collect information about the compromised computer including some basic network adapter information, system version information, and language settings.

This APT malware also investigates the strength of the victims whether the system used by a skilled person or if the victim is a high-value target.

Cybercriminals using the various command in the victim’s network to gathering the huge volume of sensitive information from network adapter information, available network shares, mapped drives, and files present on the compromised computer.

Kwampirs uses sophisticated techniques to propagate itself once inside a victim’s network by copying itself over network shares.

It established connections into a large amount of command & control servers but not all the C2 servers are active but it keeps communicate with it until it makes a successful connection.

Researchers believe that this hacking group might be work of an individual or a small group of individuals.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

LightSpy iOS Malware Enhanced with 28 New Destructive Plugins

The LightSpy threat actor exploited publicly available vulnerabilities and jailbreak kits to compromise iOS...

ATPC Cyber Forum to Focus on Next Generation Cybersecurity and Artificial Intelligence Issues

White House National Cyber Director, CEOs, Key Financial Services Companies, Congressional and Executive Branch...

New PySilon RAT Abusing Discord Platform to Maintain Persistence

Cybersecurity experts have identified a new Remote Access Trojan (RAT) named PySilon. This Trojan...

Konni APT Hackers Attacking Organizations with New Spear-Phishing Tactics

The notorious Konni Advanced Persistent Threat (APT) group has intensified its cyber assault on...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

LightSpy iOS Malware Enhanced with 28 New Destructive Plugins

The LightSpy threat actor exploited publicly available vulnerabilities and jailbreak kits to compromise iOS...

New PySilon RAT Abusing Discord Platform to Maintain Persistence

Cybersecurity experts have identified a new Remote Access Trojan (RAT) named PySilon. This Trojan...

Notorious WrnRAT Delivered Mimic As Gambling Games

WrnRAT is a new malware attack that cybercriminals have deployed by using popular gambling...