US-CERT. (2017, November 22). Alert (TA17-318A): HIDDEN COBRA – North Korean Remote Administration Tool: FALLCHILL. Retrieved December 7, 2017.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.003 Protocol or Service Impersonation |
MalwareFALLCHILL | FALLCHILL uses fake Transport Layer Security (TLS) to communicate with its C2 server. |
| T1016 System Network Configuration Discovery |
MalwareFALLCHILL | FALLCHILL collects MAC address and local IP address information from the victim. |
| T1070.004 File Deletion |
MalwareFALLCHILL | FALLCHILL can delete malware and associated artifacts from the victim. |
| T1070.006 Timestomp |
MalwareFALLCHILL | FALLCHILL can modify file or directory timestamps. |
| T1082 System Information Discovery |
MalwareFALLCHILL | FALLCHILL can collect operating system (OS) version information, processor information, and system name from the victim. |
| T1083 File and Directory Discovery |
MalwareFALLCHILL | FALLCHILL can search files on a victim. |
| T1090.002 External Proxy |
GroupLazarus Group | Lazarus Group has used multiple proxies to obfuscate network traffic from victims. |
| T1573.001 Symmetric Cryptography |
MalwareFALLCHILL | FALLCHILL encrypts C2 data with RC4 encryption. |
| T1680 Local Storage Discovery |
MalwareFALLCHILL | FALLCHILL can collect information about installed disks from the victim. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.