FALLCHILL

S0181

Malware.View on attack.mitre.org

About this malware

FALLCHILL is a RAT that has been used by Lazarus Group since at least 2016 to target the aerospace, telecommunications, and finance industries. It is usually dropped by other Lazarus Group malware or delivered when a victim unknowingly visits a compromised website.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1001.003
Protocol or Service Impersonation

FALLCHILL uses fake Transport Layer Security (TLS) to communicate with its C2 server.

T1016
System Network Configuration Discovery

FALLCHILL collects MAC address and local IP address information from the victim.

T1070.004
File Deletion

FALLCHILL can delete malware and associated artifacts from the victim.

T1070.006
Timestomp

FALLCHILL can modify file or directory timestamps.

T1082
System Information Discovery

FALLCHILL can collect operating system (OS) version information, processor information, and system name from the victim.

T1083
File and Directory Discovery

FALLCHILL can search files on a victim.

T1543.003
Windows Service

FALLCHILL has been installed as a Windows service.

T1573.001
Symmetric Cryptography

FALLCHILL encrypts C2 data with RC4 encryption.

T1680
Local Storage Discovery

FALLCHILL can collect information about installed disks from the victim.

Groups that use it1

Campaigns0

None recorded.

References1

  1. US-CERT FALLCHILL Nov 2017 Open source
    US-CERT. (2017, November 22). Alert (TA17-318A): HIDDEN COBRA – North Korean Remote Administration Tool: FALLCHILL. Retrieved December 7, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.