Attacks/Breaches

4/26/2018
09:00 AM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

US Healthcare Firms Among Dozens Hit in 'Orangeworm' Cyberattack Campaign

Attackers target healthcare organizations in apparent data theft mission, but could do far more damage, according to Symantec researchers.

Dozens of healthcare organizations, many of them in the United States, have become victims of what appears to be a highly targeted international campaign to steal data on sophisticated medical equipment and systems.

The campaign is notable for the potential it has to execute extensive damage to high-value x-ray machines, MRI systems, and other medical devices as well as their network infrastructure.

Symantec was the first to identify the previously unknown Orangeworm campaign. It found that at least 100 healthcare entities and companies in the healthcare supply chain have been hit since January 2015. About two dozen of those organizations became victims during the last half of 2017 and early part of this year.

In an advisory this week Symantec described Orangeworm as deploying Kwampirs, a custom backdoor on systems belonging to multiple healthcare organizations with international operations.

The backdoor gives the attackers full remote access to compromised machines, which they have then used to establish a persistent presence on the network. The attackers have used the backdoor to collect basic system and network information to determine if a compromised system or network is high-value or not.

If the system is high-value, Orangeworm typically copies the backdoor on other systems via open network shares. The attackers have then proceed to harvest a lot more information about the victim network including computers that have been accessed recently, mapped drives, open network shares, and information on network adapters.

For the most part, Kwampirs' functionality is similar to many other backdoors. However, it does not spread by taking advantage of vulnerabilities or exploits, says Jon DiMaggio, senior threat intelligence analyst at Symantec. Instead it relies on open shares found in the target environment to spread.

Based on the type of commands executed within victim networks and the type of information being gathered by the group, Orangeworm is conducting operations to learn about the technologies running on many of the compromised devices, says DiMaggio.

"One way this information could be leveraged is to possibly create pirated versions of the technologies the attacker is collecting information on," he says. It could also help the attackers gain a better understanding of how these systems and devices function and operate. "All of this could be used as an advantage to a competitor," DiMaggio says.

Devices running medical technology have been clearly one of the high-value targets for the group, DiMaggio says. This includes various types of x-ray and MRI devices and associated systems that interact or control the devices themselves. About 17% of the victim organizations so far are US-based, and the rest are scattered over nearly two-dozen other countries including India, Saudi Arabia, Philippines, the United Kingdom, and France.

Known victims include hospitals, pharmaceutical firms, medial equipment manufacturing firms, and providers of IT and logistics services to organizations in the healthcare sector. The list of Orangeworm's victims suggests they were specifically targeted for attack rather than randomly picked. The secondary victims appear to have been selected for the likely access they provided to the intended targets, according to Symantec.

Troubling as the espionage itself has been, the real concern is just how much access the attackers have managed to gain on compromised networks, DiMaggio says. "The Kwampirs malware used by Orangeworm provided a backdoor and allowed the attacker to load additional tools and malicious payloads at their discretion," he notes.

"The access and control the attacker had on victim systems could allow the attacker to do much worse, such as sabotage or destroy expensive medical equipment as well as the infrastructure that supports these devices."

Campaigns like Orangeworm highlight the need for organizations in the healthcare sector to start addressing some of the issues that can stem from incorporating legacy systems into production environments. Ordinarily, the security mechanisms built into many modern operating systems and security devices would have been effective in stopping Kwampirs.

"The attackers, however, were aware the healthcare vertical as a whole still relies on older platforms and technologies to host medical tech," DiMaggio says. "This allowed the attacker to use a much more primitive way to spread than it would be able to in an environment that did not include these legacy technologies."  

Even though the method used by Kwampirs to propagate and communicate with command and control servers is particularly noisy, it has worked well for them so far, according to Symantec, which thus far has no information on the origin of the attackers.

Medical Equipment at Risk

Based on Symantec's description the Kwampirs backdoor, it would not be effective against any modern security protections or up-to-date systems, says John Nye, director of cybersecurity research and communications at CynergisTek. Orangeworm is taking advantage of known issues that exist in the modern healthcare-imaging suite, which includes imaging devices such as MRI and CTs, he says.

"That is, they utilize expensive and complex systems, like MRIs and x-rays that are owned by vendors that have not taken the initiative to update or improve the security of these devices," Nye says. "This is why it is so critical for all organizations to segment any system they do not — or cannot — control away from the primary enterprise network where sensitive information is stored."

Leon Lerman, CEO of Cynerio, says hospitals and the healthcare sector in general continue to be a popular target for attackers because of just how valuable medical records and patient information is in the criminal market. Records containing protected health information for instance can fetch ten times as much as stolen credit card data in underground markets because it enables identify theft and healthcare fraud.

Related Content:

Interop ITX 2018

Join Dark Reading LIVE for a two-day Cybersecurity Crash Course at Interop ITX. Learn from the industry’s most knowledgeable IT security experts. Check out the agenda here.

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/28/2018 | 8:59:22 PM
Medical records
a popular target for attackers because of just how valuable medical records and patient information is in the criminal market. There is a black market industry obviously on medical records.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/28/2018 | 8:56:45 PM
Old technology
The attackers, however, were aware the healthcare vertical as a whole still relies on older platforms and technologies to host medical tech This may be the main reason why healthcare is an easy target.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/28/2018 | 8:54:59 PM
Heathcare
Known victims include hospitals, pharmaceutical firms, medial equipment manufacturing firms, and providers of IT and logistics services to organizations in the healthcare sector. Obviusly they see better value in healthcare organizations than others.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/28/2018 | 8:47:53 PM
Orangeworm
The campaign is notable for the potential it has to execute extensive damage to high-value x-ray machines, MRI systems, and other medical devices as well as their network infrastructure. Obviously this became new normal, there is no a day that we do not hear attack in the healthcare industry.
donkasprzak
50%
50%
donkasprzak,
User Rank: Apprentice
4/26/2018 | 12:33:10 PM
resources to impacted heathcare firms
Appreciate linkable resources to hospotals/health system impacted by orangeworm as stated.
Valentine's Emails Laced with Gandcrab Ransomware
Kelly Sheridan, Staff Editor, Dark Reading,  2/14/2019
High Stress Levels Impacting CISOs Physically, Mentally
Jai Vijayan, Freelance writer,  2/14/2019
Mozilla, Internet Society and Others Pressure Retailers to Demand Secure IoT Products
Curtis Franklin Jr., Senior Editor at Dark Reading,  2/14/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
How Enterprises Are Attacking the Cybersecurity Problem
How Enterprises Are Attacking the Cybersecurity Problem
Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-7164
PUBLISHED: 2019-02-20
SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.
CVE-2018-20025
PUBLISHED: 2019-02-19
Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0.
CVE-2018-20026
PUBLISHED: 2019-02-19
Improper Communication Address Filtering exists in CODESYS V3 products versions prior V3.5.14.0.
CVE-2018-9867
PUBLISHED: 2019-02-19
In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administrators who are not in the SonicWall Administrators user group attempt to download imported certificates. This vulnerability affected SonicOS Gen 5 version 5.9.1.10 and earlier.
CVE-2019-5780
PUBLISHED: 2019-02-19
Insufficient restrictions on what can be done with Apple Events in Google Chrome on macOS prior to 72.0.3626.81 allowed a local attacker to execute JavaScript via Apple Events.