WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home H2OSecCon 2026 FBI PIN: Kwampirs Malware Employed in Ongoing Supply Chain Campaign Targeting Global Industries
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

FBI PIN: Kwampirs Malware Employed in Ongoing Supply Chain Campaign Targeting Global Industries

Author: Charles Egli

Created: Tuesday, March 31, 2020 - 16:44

Categories: Cybersecurity

The FBI has published a Private Industry Notification (PIN) on Kwampirs, a remote access Trojan the FBI says has heavily targeted several industries, including energy and the software supply chain. As described in the PIN, a campaign with Kwampirs employs a two-phased approach. The first phase establishes a broad and persistent presence on the targeted network, to include delivery and execution of secondary malware payload(s). The second phase includes the delivery of additional Kwampirs components or malicious payload(s) to further exploit the infected victim host(s). The PIN provides further details about Kwampirs and provides recommendations for network security and defense and post-infection actions.

WaterISAC has previously provided information on Kwampirs, including for two FBI FLASH messages (the first published on January 6, 2020 and the second on February 5).

Attached Files:

Kwampirs_PIN_20200330-001

Related Resources

Members Only

(TLP:AMBER) DHS Office of Intelligence and Analysis Reports (May 21, 2026)

May 21, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Weekly Vulnerabilities to Prioritize – May 21, 2026

May 21, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:GREEN) PEAR Ransomware Claims U.S. Drinking Water Utility as Victim

May 21, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar