#FALLCHILL

Malware/Tool

2017-11-14 • HIDDEN COBRA – North Korean Remote Administration Tool: FALLCHILL

FALLCHILL is a fully functional remote access trojan used by Lazarus Group, also tracked in U.S. government reporting as HIDDEN COBRA, since at least 2016. It gives operators remote control of compromised Windows systems, including the ability to collect host information, execute commands, manage files and processes, and communicate with command-and-control infrastructure through multiple proxies. FALLCHILL has targeted organizations in the aerospace, telecommunications, and financial sectors and has been delivered by other Lazarus malware, compromised websites, and exploit-bearing documents. MITRE ATT&CK S0181.

Tagged Reports

« Back