
The FBI issued a warning on Monday that a state-sponsored hacking group is using the Kwampirs malware to carry out supply chain attacks as part of a global hacking campaigntargeting companies across a variety of industries, most notably healthcare.
This is the FBI's third warning about this hacking group in three months. The first two were published on January 6 and February 5.
This time, the FBI emphasized that some of the hackers' targets are healthcare organizations, which are currently facing a very significant problem, the coronavirus.
In addition to sending a PIN (Private Industry Notification), the FBI has also published two Flash alerts. One alert contains YARA rules for detecting the Kwampirs malware on infected networks. The second contains a technical report, with IOCs (Indicators of Compromise).
Both Flash alerts are essentially reposts of the February and January reports. However, some new information has been added.
FBI warns of supply chain attacks on healthcare organizations
The FBI named the hacking group behind the supply chain attacks Kwampirs because of the malware it uses. It described the group as an Advanced Persistent Threat (APT) , a term commonly used for state-sponsored hacking groups.
FBI investigators said the group has been active since 2016. That's when the first attacks with the Kwampirs remote access trojan (RAT).
Investigations showed that the group's victims include businesses in the healthcare, energy, engineering, software supply chain, etc. The attacks were observed on businesses in the United States, Europe, Asia, and the Middle East.

Also, the targets (although secondary) include some financial institutions and large law firms.
However, the primary target is the healthcare sector.
According to the FBI, “Kwampirs’ operations against global healthcare entities were effective”.
The hackers managed to gain “broad and persistent access” to targeted entities. The victims include international healthcare organizations as well as local hospitals.
group gained access to hospitals through supply chain attacks
The FBI believes that the Kwampirs hackers managed to gain access to a large number of hospitals through attacks on software and hardware product suppliers that equip the hospitals.
In some attacks, hackers only had access to a few machines. In others, they compromised entire business networks
As we mentioned earlier, the FBI provides details in one of its Flash alerts, regarding the detection of the malicious software.
Experts did not directly link the hackers to any country, but said their malware code has significant similarities to the Disttrack malware, known as Shamoon, which has been linked to Iranian hackers.
We don't know if the FBI's new warnings are due to increased attacks by the group during this time. It may simply have wanted to put the healthcare sector on alert.
The health sector is at risk due to the coronavirus
During this period, healthcare organizations and medical research institutions constitute one of the most significant targets of corporate hacking and espionage.
Last week, Reuters reported that a state-sponsored hacking group recently attempted to breach the World Health Organization.
