ATT&CKReferencesUS-CERT FALLCHILL Nov 2017

US-CERT FALLCHILL Nov 2017

US-CERT. (2017, November 22). Alert (TA17-318A): HIDDEN COBRA – North Korean Remote Administration Tool: FALLCHILL. Retrieved December 7, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
MalwareFALLCHILL

FALLCHILL uses fake Transport Layer Security (TLS) to communicate with its C2 server.

T1016
System Network Configuration Discovery
MalwareFALLCHILL

FALLCHILL collects MAC address and local IP address information from the victim.

T1070.004
File Deletion
MalwareFALLCHILL

FALLCHILL can delete malware and associated artifacts from the victim.

T1070.006
Timestomp
MalwareFALLCHILL

FALLCHILL can modify file or directory timestamps.

T1082
System Information Discovery
MalwareFALLCHILL

FALLCHILL can collect operating system (OS) version information, processor information, and system name from the victim.

T1083
File and Directory Discovery
MalwareFALLCHILL

FALLCHILL can search files on a victim.

T1090.002
External Proxy
GroupLazarus Group

Lazarus Group has used multiple proxies to obfuscate network traffic from victims.

T1573.001
Symmetric Cryptography
MalwareFALLCHILL

FALLCHILL encrypts C2 data with RC4 encryption.

T1680
Local Storage Discovery
MalwareFALLCHILL

FALLCHILL can collect information about installed disks from the victim.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.