KWAMPIRS

KWAMPIRSKwampirs

Description

Once Orangeworm has infiltrated a victim’s network, they deploy Trojan.Kwampirs, a backdoor Trojan that provides the attackers with remote access to the compromised computer. When executed, Kwampirs decrypts and extracts a copy of its main DLL payload from its resource section. Before writing the payload to disk, it inserts a randomly generated string into the middle of the decrypted payload in an attempt to evade hash-based detections.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
Orangeworm
Software
Kampret
Software
KCW
Software
Black Worm
Software
Brambul
Software
Naampa
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.