Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

4/26/2018
09:00 AM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

US Healthcare Firms Among Dozens Hit in 'Orangeworm' Cyberattack Campaign

Attackers target healthcare organizations in apparent data theft mission, but could do far more damage, according to Symantec researchers.

Dozens of healthcare organizations, many of them in the United States, have become victims of what appears to be a highly targeted international campaign to steal data on sophisticated medical equipment and systems.

The campaign is notable for the potential it has to execute extensive damage to high-value x-ray machines, MRI systems, and other medical devices as well as their network infrastructure.

Symantec was the first to identify the previously unknown Orangeworm campaign. It found that at least 100 healthcare entities and companies in the healthcare supply chain have been hit since January 2015. About two dozen of those organizations became victims during the last half of 2017 and early part of this year.

In an advisory this week Symantec described Orangeworm as deploying Kwampirs, a custom backdoor on systems belonging to multiple healthcare organizations with international operations.

The backdoor gives the attackers full remote access to compromised machines, which they have then used to establish a persistent presence on the network. The attackers have used the backdoor to collect basic system and network information to determine if a compromised system or network is high-value or not.

If the system is high-value, Orangeworm typically copies the backdoor on other systems via open network shares. The attackers have then proceed to harvest a lot more information about the victim network including computers that have been accessed recently, mapped drives, open network shares, and information on network adapters.

For the most part, Kwampirs' functionality is similar to many other backdoors. However, it does not spread by taking advantage of vulnerabilities or exploits, says Jon DiMaggio, senior threat intelligence analyst at Symantec. Instead it relies on open shares found in the target environment to spread.

Based on the type of commands executed within victim networks and the type of information being gathered by the group, Orangeworm is conducting operations to learn about the technologies running on many of the compromised devices, says DiMaggio.

"One way this information could be leveraged is to possibly create pirated versions of the technologies the attacker is collecting information on," he says. It could also help the attackers gain a better understanding of how these systems and devices function and operate. "All of this could be used as an advantage to a competitor," DiMaggio says.

Devices running medical technology have been clearly one of the high-value targets for the group, DiMaggio says. This includes various types of x-ray and MRI devices and associated systems that interact or control the devices themselves. About 17% of the victim organizations so far are US-based, and the rest are scattered over nearly two-dozen other countries including India, Saudi Arabia, Philippines, the United Kingdom, and France.

Known victims include hospitals, pharmaceutical firms, medial equipment manufacturing firms, and providers of IT and logistics services to organizations in the healthcare sector. The list of Orangeworm's victims suggests they were specifically targeted for attack rather than randomly picked. The secondary victims appear to have been selected for the likely access they provided to the intended targets, according to Symantec.

Troubling as the espionage itself has been, the real concern is just how much access the attackers have managed to gain on compromised networks, DiMaggio says. "The Kwampirs malware used by Orangeworm provided a backdoor and allowed the attacker to load additional tools and malicious payloads at their discretion," he notes.

"The access and control the attacker had on victim systems could allow the attacker to do much worse, such as sabotage or destroy expensive medical equipment as well as the infrastructure that supports these devices."

Campaigns like Orangeworm highlight the need for organizations in the healthcare sector to start addressing some of the issues that can stem from incorporating legacy systems into production environments. Ordinarily, the security mechanisms built into many modern operating systems and security devices would have been effective in stopping Kwampirs.

"The attackers, however, were aware the healthcare vertical as a whole still relies on older platforms and technologies to host medical tech," DiMaggio says. "This allowed the attacker to use a much more primitive way to spread than it would be able to in an environment that did not include these legacy technologies."  

Even though the method used by Kwampirs to propagate and communicate with command and control servers is particularly noisy, it has worked well for them so far, according to Symantec, which thus far has no information on the origin of the attackers.

Medical Equipment at Risk

Based on Symantec's description the Kwampirs backdoor, it would not be effective against any modern security protections or up-to-date systems, says John Nye, director of cybersecurity research and communications at CynergisTek. Orangeworm is taking advantage of known issues that exist in the modern healthcare-imaging suite, which includes imaging devices such as MRI and CTs, he says.

"That is, they utilize expensive and complex systems, like MRIs and x-rays that are owned by vendors that have not taken the initiative to update or improve the security of these devices," Nye says. "This is why it is so critical for all organizations to segment any system they do not — or cannot — control away from the primary enterprise network where sensitive information is stored."

Leon Lerman, CEO of Cynerio, says hospitals and the healthcare sector in general continue to be a popular target for attackers because of just how valuable medical records and patient information is in the criminal market. Records containing protected health information for instance can fetch ten times as much as stolen credit card data in underground markets because it enables identify theft and healthcare fraud.

Related Content:

Interop ITX 2018

Join Dark Reading LIVE for a two-day Cybersecurity Crash Course at Interop ITX. Learn from the industry’s most knowledgeable IT security experts. Check out the agenda here.

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/28/2018 | 8:59:22 PM
Medical records
a popular target for attackers because of just how valuable medical records and patient information is in the criminal market. There is a black market industry obviously on medical records.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/28/2018 | 8:56:45 PM
Old technology
The attackers, however, were aware the healthcare vertical as a whole still relies on older platforms and technologies to host medical tech This may be the main reason why healthcare is an easy target.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/28/2018 | 8:54:59 PM
Heathcare
Known victims include hospitals, pharmaceutical firms, medial equipment manufacturing firms, and providers of IT and logistics services to organizations in the healthcare sector. Obviusly they see better value in healthcare organizations than others.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/28/2018 | 8:47:53 PM
Orangeworm
The campaign is notable for the potential it has to execute extensive damage to high-value x-ray machines, MRI systems, and other medical devices as well as their network infrastructure. Obviously this became new normal, there is no a day that we do not hear attack in the healthcare industry.
donkasprzak
50%
50%
donkasprzak,
User Rank: Apprentice
4/26/2018 | 12:33:10 PM
resources to impacted heathcare firms
Appreciate linkable resources to hospotals/health system impacted by orangeworm as stated.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/14/2020
Lock-Pickers Face an Uncertain Future Online
Seth Rosenblatt, Contributing Writer,  8/10/2020
Hacking It as a CISO: Advice for Security Leadership
Kelly Sheridan, Staff Editor, Dark Reading,  8/10/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 New Cybersecurity Vulnerabilities That Could Put Your Enterprise at Risk
In this Dark Reading Tech Digest, we look at the ways security researchers and ethical hackers find critical vulnerabilities and offer insights into how you can fix them before attackers can exploit them.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-17475
PUBLISHED: 2020-08-14
Lack of authentication in the network relays used in MEGVII Koala 2.9.1-c3s allows attackers to grant physical access to anyone by sending packet data to UDP port 5000.
CVE-2020-0255
PUBLISHED: 2020-08-14
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-10751. Reason: This candidate is a duplicate of CVE-2020-10751. Notes: All CVE users should reference CVE-2020-10751 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidenta...
CVE-2020-14353
PUBLISHED: 2020-08-14
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-18270. Reason: This candidate is a duplicate of CVE-2017-18270. Notes: All CVE users should reference CVE-2017-18270 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidenta...
CVE-2020-17464
PUBLISHED: 2020-08-14
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2020-17473
PUBLISHED: 2020-08-14
Lack of mutual authentication in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to obtain a long-lasting token by impersonating the server.