Symantec announces new cyber threat to healthcare organisations
US software company Symantec has recently announced its recent findings surrounding an ongoing cyber threat to the healthcare industry.
Named Orangeworm, the cyber attack has affected up to 100 organisations, situated in the US (17%), Europe and Asia, the company has reported.
"According to Symantec telemetry, almost 40% of Orangeworm’s confirmed victim organizations operate within the healthcare industry."
"The Kwampirs malware was found on machines which had software installed for the use and control of high-tech imaging devices such as X-Ray and MRI machines.
“Additionally, Orangeworm was observed to have an interest in machines used to assist patients in completing consent forms for required procedures," the company added.
The malware is able to replicate itself over various network, making its worm-like actions inaccessible by outdated virus software and IT systems, such as Windows XP, which have been found to remain rampant across the industry.
However, the malware has also impacted supply chains, IT, pharmaceutical and manufacturing companies who work with healthcare providers. Targeting a number of industries has therefore heightened the range of information which hackers can obtain.
“What they do is clearly aimed at collecting information across the entire healthcare supply chain of their targets. You don’t really see that. What we’re seeing is corporate espionage, not for the sake of sabotage or destruction of equipment, and not for financial gain,” explained Jon DiMaggio, Senior Threat Intelligence Researcher at Symantec.
“The attackers cast a wide net and then choose high-value targets out of the sample. From there, they spend an immense amount of time trying to learn the ins and outs of the target’s systems, including seeking out directories, finding out what everything’s connected to, finding open shares.
- Blockchain can pave the way for a more value-based healthcare system, report suggests
- Navigating regulations to launch OTC consumer health products
- Who should be responsible for the implementation of health wearables?
“This is speculation, but if they had source code or pirated technology, it would fit the story and would explain why they’re so interested in how things operate. But that’s just a theory.
“The situation could be so much worse; these guys have the capability to wipe hard drives or destroy equipment,” he continues.
“Implementing basic security procedures like patching and network segmentation would prevent this threat with minimal work. And, the healthcare community as a whole needs to push their software vendors to consider security more so than ease-of-use.”
Jalal Bouhdada, Founder and Principal ICS Security Consultant for Applied Risk, also outlined why "security by design" is crucial to cure security issues in the healthcare industry.
“It is perhaps no surprise that a new attack group, dubbed Orangeworm, has been discovered targeting the healthcare industry. There have been repeated warnings that healthcare systems are easy pickings for cybercriminals, and although there has been an understandable desire within the industry to press ahead and unlock the benefits of IoT technology, a lack of consideration regarding the security ramifications of this has begun to concern many,” he says.
“While innovation in the healthcare industry is having a great impact on the quality of life for many people, what if the opposite is also true? While in the case of Orangeworm it seems the attackers were only looking to learn about the inner workings of a system, could this often life-saving medical equipment be turned against us?
“There has been much speculation over potential scenarios in which devices such as insulin pumps are hijacked and held to ransom; or terrorists attack connected pacemakers en masse. Sadly, this is no longer the stuff of fiction, as made clear by the FDA’s recent warnings regarding exploitable flaws in connected cardiac pacemakers. Medical device manufacturers must come to terms with the idea that the security of the healthcare equipment itself is also a life and death issue.
“Medical device manufacturers must now begin adhering to best practice security advice. New data privacy laws and strict FDA requirements mean the responsibility is now with the developers to ensure the protection of networks and systems, or they will face the consequences.
“To help meet these obligations, the security industry and medical device manufacturers must develop a closer relationship, ensuring that new devices are developed with security defences baked in. The ethos of “secure by design” must become entrenched within all product developers."