Skip to content
September 29, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Cyber Security
  • Orangeworm hackers group attack the hospital’s X-Ray and MRI machines
  • Cyber Security

Orangeworm hackers group attack the hospital’s X-Ray and MRI machines

Do Son April 24, 2018 3 minutes read
Orangeworm
Add Daily CyberSecurity as a preferred source on Google

Symantec cybersecurity researchers discovered a hacker group, Orangeworm, which launched a network attack on medical devices. The group installed Trojan worms on various types of computers that control high-tech medical devices in hospitals. Including not only X-ray machines and MRI machines, but also some computers that assist patients in completing various consent forms are also infected with malware.

The hacking organization has been active since 2015. Its main target is for multinational corporations in the United States and Europe. The target in Asia is mainly for medical institutions. After hacking into the network of medical institutions, a Trojan horse named Kwampirs will be installed on the computer, allowing hackers to remotely control the computer and obtain the data.

In the process of data decryption, Kwampirs will randomly generate a field in the main program’s dynamic link library (DLL), which can avoid being monitored by the hash, and it also stays in the background of the system and starts the service that is started automatically. The computer on which the Kwampirs malware is installed will communicate with the hacker’s remote server. The hacker will choose the appropriate hacking tool to steal the required data based on the operating system and value of the target computer.

If the target computer is of high value, Kwampirs malware will become more aggressive and spread to other computers in the same network. The cleverness of Kwampirs is that it does not use other command lines to control, and only use the commands that the system comes with to obtain the required data. The command line shown in the figure above can steal “any relevant information on the target computer, including network cards, available network shares, mounted hard disk partitions, and files”.

The study found that Orangeworm’s goal is 40% of medical institutions and pharmaceutical companies, in addition to IT industry, manufacturing, agriculture, logistics and other industries also have aggressive behavior. Of course, many of the latter industries are also indirectly related to the medical industry. For example, manufacturing refers to companies that manufacture related equipment for the medical industry; IT industry refers to companies that provide software services for medical institutions, and the logistics industry is also Various medical institutions provide related equipment and pharmaceutical transport service companies.

It is not yet clear what the motivation of Orangeworm is, nor does it know the history of the hacking organization. Symantec believes that the hacking organization is mainly for commercial espionage and has not yet discovered the connection between the organization and certain countries. Based on the current case finding, the organization will not randomly select the target of the attack. A detailed plan will be prepared before the attack is implemented. Most of the companies that have been attacked are in the United States, and some are in Saudi Arabia, India, the Philippines, Hungary, the United Kingdom, Turkey, Germany, Poland, Hong Kong, Sweden, Canada, and France.

Related coverage

  • Tall Tales: China’s Private Contractors and the Global Hunt for Dissent
  • Star Blizzard Shifts Tactics: Spear-Phishing Campaign Targets WhatsApp Accounts
  • North Korea’s Cyber Shadow War: Unmasking RustBucket and KandyKorn
  • AeroBlade: The Stealth Cyber Threat to the U.S. Aerospace Industry
  • Decade of Stealth: China-Linked TA-ShadowCricket Targets Asia-Pacific
  • Unmasking Silver Dragon: The Chinese-Nexus APT Haunting Southeast Asia and Europe
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Orangeworm

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-88771
    Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 23, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-69431CVSS 9.8
    Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network.
    📅 Updated: Sep 29, 2026
  • CVE-2026-7192CVSS 9.3
    A stack-based buffer overflow vulnerability in the Dbit T-CPE301K 4G WiFi minirouter allows an authenticated attacker to cause...
    📅 Updated: Sep 29, 2026
  • CVE-2026-22094CVSS 9.3
    The firmware for the EVbee DC-80 has a weak hardcoded root password, which allows attackers to login as...
    📅 Updated: Sep 29, 2026
  • CVE-2026-102268CVSS 9.1
    PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py is affected...
    📅 Updated: Sep 29, 2026
  • CVE-2026-100818CVSS 9.6
    Sandbox escape due to use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox ESR 153.4,...
    📅 Updated: Sep 29, 2026
  • CVE-2025-15039CVSS 9.4
    The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when...
    📅 Updated: Sep 29, 2026
  • CVE-2026-6928CVSS 9.8
    IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker...
    📅 Updated: Sep 29, 2026
  • CVE-2026-92035CVSS 9.6
    Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 156,...
    📅 Updated: Sep 29, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.