#FALLCHILL
Malware/Tool
2017-11-14 • HIDDEN COBRA – North Korean Remote Administration Tool: FALLCHILL
FALLCHILL is a fully functional remote access trojan used by Lazarus Group, also tracked in U.S. government reporting as HIDDEN COBRA, since at least 2016. It gives operators remote control of compromised Windows systems, including the ability to collect host information, execute commands, manage files and processes, and communicate with command-and-control infrastructure through multiple proxies. FALLCHILL has targeted organizations in the aerospace, telecommunications, and financial sectors and has been delivered by other Lazarus malware, compromised websites, and exploit-bearing documents. MITRE ATT&CK S0181.
-
7
Tagged Reports
-
6
Unique Authors
-
2,114
Active Days