Tuesday, March 4, 2025
HomeCyber AttackAPT Group Cyber Attack Against Medical Sectors to Hack X-Ray & MRI...

APT Group Cyber Attack Against Medical Sectors to Hack X-Ray & MRI Scan Machines

Published on

SIEM as a Service

Follow Us on Google News

New APT Cyber espionage group Orangeworm targeting healthcare sectors and other medical related industries to deploy the powerful Kwampirs backdoor to compromise the medical devices such as X-Ray & MRI Scan Machines.

Kwampirs backdoor initially discovered in 2016 that can able to open a potential backdoor in compromised computers to steal the sensitive information and also download malicious files.

The orangeworm APT cyber group mainly targeting healthcare sector in the U.S., Europe, Asia and they are active since 2015.

Apart From Healthcare industries, Orangeworm APT also targeting the related industries such as healthcare providers, pharmaceuticals, IT solution providers for healthcare and equipment manufacturers that serve the healthcare industry.

This is one of the well-planned attack against the medical industries with a good amount of planning before they attack the specific industries.

Orangeworm high amount of attack registered against Healthcare industries and other related industries also infected followed by Healthcare.

According to Symantec, We believe that these industries have also been targeted as part of a larger supply-chain attack in order for Orangeworm to get access to their intended victims related to healthcare. Orangeworm’s secondary targets include Manufacturing, Information Technology, Agriculture, and Logistics.

Also Read:  Best Ways to Prepare Your Organization For Cyber Disasters

Orangeworm Attack Against X-Ray and MRI Machines 

Kwampirs backdoor discovered within the software that used to control the medical equipment such as  X-Ray and MRI machines and also Orangeworm was recognized to have an interest in machines used to assist patients.

The biggest amount of victims have been identified in the U.S with 17 percent of the infection and India, Saudi Arabia, Philippines etc countries are severely affected next to the U.S.

Initial infection leads to compromise the network and deploy the Kwampirs backdoor that takes a remote control of the victim’s machine.

During the infection, it using randomly generated string to decrypt the payload to evade the signature-based detection.

Also, it performs various tasks to maintin its persistence and this backdoor collect information about the compromised computer including some basic network adapter information, system version information, and language settings.

This APT malware also investigates the strength of the victims whether the system used by a skilled person or if the victim is a high-value target.

Cybercriminals using the various command in the victim’s network to gathering the huge volume of sensitive information from network adapter information, available network shares, mapped drives, and files present on the compromised computer.

Kwampirs uses sophisticated techniques to propagate itself once inside a victim’s network by copying itself over network shares.

It established connections into a large amount of command & control servers but not all the C2 servers are active but it keeps communicate with it until it makes a successful connection.

Researchers believe that this hacking group might be work of an individual or a small group of individuals.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Update Alert: Google Warns of Critical Android Vulnerabilities Under Exploit

Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under...

BigAnt Server 0-Day Vulnerability Lets Attackers Run Malicious Code Remotely

A critical vulnerability in BigAntSoft's enterprise chat server software has exposed ~50 internet-facing systems...

Bubba AI, Inc. is Launching Comp AI to Help 100,000 Startups Get SOC 2 Compliant by 2032.

With the growing importance of security compliance for startups, more companies are seeking to...

IBM Storage Virtualize Flaws Allow Remote Code Execution

Two critical security flaws in IBM Storage Virtualize products could enable attackers to bypass...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

33.3 Million Cyber Attacks Targeted Mobile Devices in 2024 as Threats Surge

Kaspersky's latest report on mobile malware evolution in 2024 reveals a significant increase in...

New Pass-the-Cookie Attacks Bypass MFA, Giving Hackers Full Account Access

Multi-factor authentication (MFA), long considered a cornerstone of cybersecurity defense, is facing a formidable...

Winos4.0 Malware Targets Windows Users Through Malicious PDF Files

A new wave of cyberattacks leveraging the Winos4.0 malware framework has targeted organizations in...