Attacks/Breaches

4/26/2018
09:00 AM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

US Healthcare Firms Among Dozens Hit in 'Orangeworm' Cyberattack Campaign

Attackers target healthcare organizations in apparent data theft mission, but could do far more damage, according to Symantec researchers.

Dozens of healthcare organizations, many of them in the United States, have become victims of what appears to be a highly targeted international campaign to steal data on sophisticated medical equipment and systems.

The campaign is notable for the potential it has to execute extensive damage to high-value x-ray machines, MRI systems, and other medical devices as well as their network infrastructure.

Symantec was the first to identify the previously unknown Orangeworm campaign. It found that at least 100 healthcare entities and companies in the healthcare supply chain have been hit since January 2015. About two dozen of those organizations became victims during the last half of 2017 and early part of this year.

In an advisory this week Symantec described Orangeworm as deploying Kwampirs, a custom backdoor on systems belonging to multiple healthcare organizations with international operations.

The backdoor gives the attackers full remote access to compromised machines, which they have then used to establish a persistent presence on the network. The attackers have used the backdoor to collect basic system and network information to determine if a compromised system or network is high-value or not.

If the system is high-value, Orangeworm typically copies the backdoor on other systems via open network shares. The attackers have then proceed to harvest a lot more information about the victim network including computers that have been accessed recently, mapped drives, open network shares, and information on network adapters.

For the most part, Kwampirs' functionality is similar to many other backdoors. However, it does not spread by taking advantage of vulnerabilities or exploits, says Jon DiMaggio, senior threat intelligence analyst at Symantec. Instead it relies on open shares found in the target environment to spread.

Based on the type of commands executed within victim networks and the type of information being gathered by the group, Orangeworm is conducting operations to learn about the technologies running on many of the compromised devices, says DiMaggio.

"One way this information could be leveraged is to possibly create pirated versions of the technologies the attacker is collecting information on," he says. It could also help the attackers gain a better understanding of how these systems and devices function and operate. "All of this could be used as an advantage to a competitor," DiMaggio says.

Devices running medical technology have been clearly one of the high-value targets for the group, DiMaggio says. This includes various types of x-ray and MRI devices and associated systems that interact or control the devices themselves. About 17% of the victim organizations so far are US-based, and the rest are scattered over nearly two-dozen other countries including India, Saudi Arabia, Philippines, the United Kingdom, and France.

Known victims include hospitals, pharmaceutical firms, medial equipment manufacturing firms, and providers of IT and logistics services to organizations in the healthcare sector. The list of Orangeworm's victims suggests they were specifically targeted for attack rather than randomly picked. The secondary victims appear to have been selected for the likely access they provided to the intended targets, according to Symantec.

Troubling as the espionage itself has been, the real concern is just how much access the attackers have managed to gain on compromised networks, DiMaggio says. "The Kwampirs malware used by Orangeworm provided a backdoor and allowed the attacker to load additional tools and malicious payloads at their discretion," he notes.

"The access and control the attacker had on victim systems could allow the attacker to do much worse, such as sabotage or destroy expensive medical equipment as well as the infrastructure that supports these devices."

Campaigns like Orangeworm highlight the need for organizations in the healthcare sector to start addressing some of the issues that can stem from incorporating legacy systems into production environments. Ordinarily, the security mechanisms built into many modern operating systems and security devices would have been effective in stopping Kwampirs.

"The attackers, however, were aware the healthcare vertical as a whole still relies on older platforms and technologies to host medical tech," DiMaggio says. "This allowed the attacker to use a much more primitive way to spread than it would be able to in an environment that did not include these legacy technologies."  

Even though the method used by Kwampirs to propagate and communicate with command and control servers is particularly noisy, it has worked well for them so far, according to Symantec, which thus far has no information on the origin of the attackers.

Medical Equipment at Risk

Based on Symantec's description the Kwampirs backdoor, it would not be effective against any modern security protections or up-to-date systems, says John Nye, director of cybersecurity research and communications at CynergisTek. Orangeworm is taking advantage of known issues that exist in the modern healthcare-imaging suite, which includes imaging devices such as MRI and CTs, he says.

"That is, they utilize expensive and complex systems, like MRIs and x-rays that are owned by vendors that have not taken the initiative to update or improve the security of these devices," Nye says. "This is why it is so critical for all organizations to segment any system they do not — or cannot — control away from the primary enterprise network where sensitive information is stored."

Leon Lerman, CEO of Cynerio, says hospitals and the healthcare sector in general continue to be a popular target for attackers because of just how valuable medical records and patient information is in the criminal market. Records containing protected health information for instance can fetch ten times as much as stolen credit card data in underground markets because it enables identify theft and healthcare fraud.

Related Content:

Interop ITX 2018

Join Dark Reading LIVE for a two-day Cybersecurity Crash Course at Interop ITX. Learn from the industry’s most knowledgeable IT security experts. Check out the agenda here.

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/28/2018 | 8:59:22 PM
Medical records
a popular target for attackers because of just how valuable medical records and patient information is in the criminal market. There is a black market industry obviously on medical records.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/28/2018 | 8:56:45 PM
Old technology
The attackers, however, were aware the healthcare vertical as a whole still relies on older platforms and technologies to host medical tech This may be the main reason why healthcare is an easy target.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/28/2018 | 8:54:59 PM
Heathcare
Known victims include hospitals, pharmaceutical firms, medial equipment manufacturing firms, and providers of IT and logistics services to organizations in the healthcare sector. Obviusly they see better value in healthcare organizations than others.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/28/2018 | 8:47:53 PM
Orangeworm
The campaign is notable for the potential it has to execute extensive damage to high-value x-ray machines, MRI systems, and other medical devices as well as their network infrastructure. Obviously this became new normal, there is no a day that we do not hear attack in the healthcare industry.
donkasprzak
50%
50%
donkasprzak,
User Rank: Apprentice
4/26/2018 | 12:33:10 PM
resources to impacted heathcare firms
Appreciate linkable resources to hospotals/health system impacted by orangeworm as stated.
New Cold Boot Attack Gives Hackers the Keys to PCs, Macs
Kelly Sheridan, Staff Editor, Dark Reading,  9/13/2018
Yahoo Class-Action Suits Set for Settlement
Dark Reading Staff 9/17/2018
RDP Ports Prove Hot Commodities on the Dark Web
Kelly Sheridan, Staff Editor, Dark Reading,  9/17/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-17208
PUBLISHED: 2018-09-19
Linksys Velop 1.1.2.187020 devices allow unauthenticated command injection, providing an attacker with full root access, via cgi-bin/zbtest.cgi or cgi-bin/zbtest2.cgi (scripts that can be discovered with binwalk on the firmware, but are not visible in the web interface). This occurs because shell me...
CVE-2018-17205
PUBLISHED: 2018-09-19
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c. During bundle commit, flows that are added in a bundle are applied to ofproto in order. If a flow cannot be added (e.g., the flow action is a go-to for a group id that does not ex...
CVE-2018-17206
PUBLISHED: 2018-09-19
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.
CVE-2018-17207
PUBLISHED: 2018-09-19
An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.
CVE-2017-2855
PUBLISHED: 2018-09-19
An exploitable buffer overflow vulnerability exists in the DDNS client used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. On devices with DDNS enabled, an attacker who is able to intercept HTTP connections will be able to fully compromise the device by creating a rogue HT...