S0236: Kwampirs
Security context for executives and security teams
S0236: Kwampirs describes [Kwampirs](https://attack.mitre.org/software/S0236) is a backdoor Trojan used by [Orangeworm](https://attack.mitre.org/groups/G0071). [Kwampirs](https://attack.mitre.org/software/S0236) has been found on machines which had software installed for the use and control of high-tech imaging devices such as X-Ray and MRI machines.(Citation: Symantec Orangeworm April 2018) [Kwampirs](https://attack.mitre.org/software/S0236) has multiple technical overlaps with [Shamoon](https://attack.mitre.org/software/S0140) based on re...
Executive priority
S0236: Kwampirs is an official MITRE ATT&CK software. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate S0236: Kwampirs by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (Windows), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
- Network, endpoint, and security-tool telemetry
Detection direction
- Validate whether S0236: Kwampirs appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Kwampirs
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1069.002 | Domain GroupsSub-technique | |
| Enterprise | T1087.001 | Local AccountSub-technique | |
| Enterprise | T1135 | Network Share Discovery | |
| Enterprise | T1140 | Deobfuscate/Decode Files or Information | |
| Enterprise | T1007 | System Service Discovery | |
| Enterprise | T1083 | File and Directory Discovery | |
| Enterprise | T1027.013 | Encrypted/Encoded FileSub-technique | Kwampirs downloads additional files that are base64-encoded and encrypted with another cipher.CitationSymantec Security Center Trojan.Kwampirs |
| Enterprise | T1543.003 | Windows ServiceSub-technique | |
| Enterprise | T1033 | System Owner/User Discovery | |
| Enterprise | T1018 | Remote System Discovery | |
| Enterprise | T1021.002 | SMB/Windows Admin SharesSub-technique | |
| Enterprise | T1027.001 | Binary PaddingSub-technique | |
| Enterprise | T1105 | Ingress Tool Transfer | Kwampirs downloads additional files from C2 servers.CitationSymantec Security Center Trojan.Kwampirs |
| Enterprise | T1082 | System Information Discovery | Kwampirs collects OS version information such as registered owner details, manufacturer details, processor type, available storage, installed patches, hostname, version info, system date, and other system information by using the commands |
| Enterprise | T1036.004 | Masquerade Task or ServiceSub-technique | |
| Enterprise | T1218.011 | Rundll32Sub-technique | |
| Enterprise | T1057 | Process Discovery | |
| Enterprise | T1049 | System Network Connections Discovery | |
| Enterprise | T1016 | System Network Configuration Discovery | |
| Enterprise | T1201 | Password Policy Discovery | |
| Enterprise | T1008 | Fallback Channels | |
| Enterprise | T1069.001 | Local GroupsSub-technique |
Groups, software, and campaigns
G0071: Orangeworm
Orangeworm is a group that has targeted organizations in the healthcare sector in the United States, Europe, and Asia since at least 2015, likely for the purpose of corporate espionage.[1] Reverse engineering of Kwampirs, directly associated with Orangeworm activity, indicates significant functional and development overlaps with Shamoon.[2]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.2 | Current bundle | 7621a6f0dbb9… | ||
| 19.1 | 1.2 | Older bundle | 7621a6f0dbb9… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Symantec Orangeworm April 2018
Symantec Security Response Attack Investigation Team. (2018, April 23). New Orangeworm attack group targets the healthcare sector in the U.S., Europe, and Asia. Retrieved May 8, 2018.
Open source URL - [2]Cylera Kwampirs 2022
Pablo Rincón Crespo. (2022, January). The link between Kwampirs (Orangeworm) and Shamoon APTs. Retrieved February 8, 2024.
Open source URL - [3]Kwampirs
(Citation: Symantec Orangeworm April 2018)
- [4]mitre-attackS0236Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
