Earlier this month, ZDNet broke the news that the FBI had sent a cybersecurity alert to the U.S. private sector warning of an ongoing hacking campaign against supply chain software providers. According to the FBI, hackers are attempting to infect upstream companies — particularly those in the energy sector — with the Kwampirs malware, a remote access trojan (RAT).
“Software supply chain companies are believed to be targeted in order to gain access to the victim's strategic partners and/or customers, including entities supporting Industrial Control Systems (ICS) for global energy generation, transmission, and distribution," said the alert.
The origins of Kwampirs
The Kwampirs malware, first identified by Symantec two years ago, was developed by a previously unknown attack group called “Orangeworm.”
Orangeworm is unique from other headline-making bad actors because it has been known to install the malware as part of larger supply chain attacks in order to get to its intended victims. In the past, these have included systematic attacks against healthcare and medical equipment manufacturers that serve the healthcare industry — a lucrative target for hackers who seek access to personal healthcare data or have other nefarious objectives.
“We believe that these industries have also been targeted as part of a larger supply-chain attack in order for Orangeworm to get access to their intended victims related to healthcare,” warned Symantec.
The growing cyber risk in the vendor ecosystem
As Orangeworm sets its sights on the energy sector, the FBI alert adds credence to a growing cybersecurity concern that many organizations overlook — that third, fourth, and even nth parties are one of the fastest-growing risks to their sensitive data. Bad actors are increasingly realizing that the easiest route into a company’s networks and systems is via its interconnected vendor ecosystem.
Indeed, a 2018 study by the Ponemon Institute found that 61% of U.S. companies have experienced a breach “caused by one of their vendors or third parties” — and that number is growing. More than 75% of organizations believe that third-party cybersecurity incidents are increasing.