Netskope Threat Labs

Kwampirs

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Kwampirs is a backdoor trojan used by the Orangeworm threat actor, found on machines running software that controls high-tech imaging devices such as X-ray and MRI machines. Researchers have noted multiple technical overlaps with the Shamoon wiper based on reverse engineering.

First seen
February 2022
Last seen
October 2026

22 techniques across 5 tactics.

TA0003 Persistence

TA0005 Stealth

TA0007 Discovery

  • T1007System Service Discovery
  • T1016System Network Configuration Discovery
  • T1018Remote System Discovery
  • T1033System Owner/User Discovery
  • T1049System Network Connections Discovery
  • T1057Process Discovery
  • T1069Permission Groups Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery
  • T1087Account Discovery
  • T1135Network Share Discovery
  • T1201Password Policy Discovery

TA0008 Lateral Movement

TA0011 Command and Control

Alert Name
Trojan.Kwampirs.A
Trojan.Kwampirs.B
Trojan.Kwampirs.C
Trojan.Kwampirs.D
Trojan.Kwampirs.E
Trojan.Kwampirs.F
Win32.Backdoor.Kwampirs
Win32.Trojan.Kwampirs