FBI Alert CP 000118-MW TLP White: YARA Rules to Identify Kwampirs Malware Employed in Ongoing

FBI Alert CP 000118-MW TLP White:

YARA Rules to Identify Kwampirs Malware Employed in Ongoing Cyber Supply Chain Campaign Targeting Global Industries

March 25, 2020

This is a re-release of FBI FLASH message (CP-000118-MW) previously disseminated on 05 February 2020.

The FBI has identified additional information regarding the Kwampirs Remote Access Trojan (RAT), which has targeted several global industries, including the software supply chain, healthcare, energy, and financial sectors. Software supply chain companies are believed to be targeted in order to gain access to the victim’s strategic partners and/or customers, including entities that support Industrial Control Systems (ICS) for global energy generation, transmission, and distribution. The Kwampirs RAT has been observed by the FBI supporting targeted computer intrusions on these sectors, including supporting additional module execution on the targeted victim network, believed to enable follow-on computer network exploitation operations.