Malware.View on attack.mitre.org
Kwampirs is a backdoor Trojan used by Orangeworm. Kwampirs has been found on machines which had software installed for the use and control of high-tech imaging devices such as X-Ray and MRI machines. Kwampirs has multiple technical overlaps with Shamoon based on reverse engineering analysis.
| Technique | Procedure example |
|---|---|
| T1007 System Service Discovery |
Kwampirs collects a list of running services with the command |
| T1008 Fallback Channels |
Kwampirs uses a large list of C2 servers that it cycles through until a successful connection is established. |
| T1016 System Network Configuration Discovery |
Kwampirs collects network adapter and interface information by using the commands |
| T1018 Remote System Discovery |
Kwampirs collects a list of available servers with the command |
| T1021.002 SMB/Windows Admin Shares |
Kwampirs copies itself over network shares to move laterally on a victim network. |
| T1027.001 Binary Padding |
Before writing to disk, Kwampirs inserts a randomly generated string into the middle of the decrypted payload in an attempt to evade hash-based detections. |
| T1027.013 Encrypted/Encoded File |
Kwampirs downloads additional files that are base64-encoded and encrypted with another cipher. |
| T1033 System Owner/User Discovery |
Kwampirs collects registered owner details by using the commands |
| T1036.004 Masquerade Task or Service |
Kwampirs establishes persistence by adding a new service with the display name "WMI Performance Adapter Extension" in an attempt to masquerade as a legitimate WMI service. |
| T1049 System Network Connections Discovery |
Kwampirs collects a list of active and listening connections by using the command |
| T1057 Process Discovery |
Kwampirs collects a list of running services with the command |
| T1069.001 Local Groups |
Kwampirs collects a list of users belonging to the local users and administrators groups with the commands |
| T1069.002 Domain Groups |
Kwampirs collects a list of domain groups with the command |
| T1082 System Information Discovery |
Kwampirs collects OS version information such as registered owner details, manufacturer details, processor type, available storage, installed patches, hostname, version info, system date, and other system information by using the commands |
| T1083 File and Directory Discovery |
Kwampirs collects a list of files and directories in C:\ with the command |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.