Skip to content

G0071 Orangeworm

Orangeworm is a group that has targeted organizations in the healthcare sector in the United States, Europe, and Asia since at least 2015, likely for the purpose of corporate espionage.1

Item Value
ID G0071
Associated Names
Version 1.1
Created 17 October 2018
Last Modified 26 October 2021
Navigation Layer View In ATT&CK® Navigator

Techniques Used

Domain ID Name Use
enterprise T1071 Application Layer Protocol -
enterprise T1071.001 Web Protocols Orangeworm has used HTTP for C2.2
enterprise T1021 Remote Services -
enterprise T1021.002 SMB/Windows Admin Shares Orangeworm has copied its backdoor across open network shares, including ADMIN$, C$WINDOWS, D$WINDOWS, and E$WINDOWS.1

Software

ID Name References Techniques
S0099 Arp 1 Remote System Discovery System Network Configuration Discovery
S0106 cmd 1 Windows Command Shell:Command and Scripting Interpreter File and Directory Discovery File Deletion:Indicator Removal Ingress Tool Transfer Lateral Tool Transfer System Information Discovery
S0100 ipconfig 1 System Network Configuration Discovery
S0236 Kwampirs 1 Local Account:Account Discovery Windows Service:Create or Modify System Process Deobfuscate/Decode Files or Information Fallback Channels File and Directory Discovery Ingress Tool Transfer Masquerade Task or Service:Masquerading Network Share Discovery Obfuscated Files or Information Binary Padding:Obfuscated Files or Information Password Policy Discovery Local Groups:Permission Groups Discovery Domain Groups:Permission Groups Discovery Process Discovery SMB/Windows Admin Shares:Remote Services Remote System Discovery Rundll32:System Binary Proxy Execution System Information Discovery System Network Configuration Discovery System Network Connections Discovery System Owner/User Discovery System Service Discovery
S0039 Net 1 Domain Account:Account Discovery Local Account:Account Discovery Local Account:Create Account Domain Account:Create Account Network Share Connection Removal:Indicator Removal Network Share Discovery Password Policy Discovery Local Groups:Permission Groups Discovery Domain Groups:Permission Groups Discovery SMB/Windows Admin Shares:Remote Services Remote System Discovery System Network Connections Discovery System Service Discovery Service Execution:System Services System Time Discovery
S0104 netstat 1 System Network Connections Discovery
S0103 route 1 System Network Configuration Discovery
S0096 Systeminfo 1 System Information Discovery

References