Malware.View on attack.mitre.org
FALLCHILL is a RAT that has been used by Lazarus Group since at least 2016 to target the aerospace, telecommunications, and finance industries. It is usually dropped by other Lazarus Group malware or delivered when a victim unknowingly visits a compromised website.
| Technique | Procedure example |
|---|---|
| T1001.003 Protocol or Service Impersonation |
FALLCHILL uses fake Transport Layer Security (TLS) to communicate with its C2 server. |
| T1016 System Network Configuration Discovery |
FALLCHILL collects MAC address and local IP address information from the victim. |
| T1070.004 File Deletion |
FALLCHILL can delete malware and associated artifacts from the victim. |
| T1070.006 Timestomp |
FALLCHILL can modify file or directory timestamps. |
| T1082 System Information Discovery |
FALLCHILL can collect operating system (OS) version information, processor information, and system name from the victim. |
| T1083 File and Directory Discovery |
FALLCHILL can search files on a victim. |
| T1543.003 Windows Service |
FALLCHILL has been installed as a Windows service. |
| T1573.001 Symmetric Cryptography |
FALLCHILL encrypts C2 data with RC4 encryption. |
| T1680 Local Storage Discovery |
FALLCHILL can collect information about installed disks from the victim. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.