FALLCHILL is a Remote Administration Tool (RAT) associated with North Korean threat activity and attributed by the U.S. Government to HIDDEN COBRA/Lazarus-linked operations. The content states it has been used in the AppleJeus cryptocurrency-targeting campaign, including the Celas Trade Pro incident, where a trojanized cryptocurrency application led to FALLCHILL infection. It is also referenced alongside other Lazarus-associated malware families such as DTrack and Manuscrypt.
Observed capabilities in the provided content include installation as a Windows service for persistence, collection of victim MAC address and local IP address information, RC4 encryption of command-and-control data, use of fake TLS to communicate with its C2 server, modification of file or directory timestamps for defense evasion/anti-forensics, and deletion of malware and associated artifacts from the victim. The content also references FALLCHILL version progression from v1.2 to v1.3.
Targeting context directly mentioned in the content includes cryptocurrency users, exchanges, financial services firms, and organizations across multiple sectors and countries through the broader AppleJeus activity. High-confidence indicators and detection context explicitly mentioned include YARA content identifying the family as "FALLCHILL."
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The cybersecurity company that published the report states the payload was an encrypted and obfuscated binary ( Obfuscated Files or Information [T1027])... The program CrashReporter.exe is heavily obfuscated...
Examples throughout the content include deleting tools, logs, malware-related files, staged archives, screenshots, temporary files, and exfiltrated data 'to cover their tracks,' 'reduce their footprint,' 'remove traces of activity,' or as part of 'post-intrusion cleanup.'
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
Updater.exe ... collects the victim’s host information ( System Owner/User Discovery [T1033]), encrypts the collected information ... and sends information to a C2 website.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... FALLCHILL ... (v1.2→v1.3) ...
FALLCHILL (v1.2→v1.3)
Lazarus-associated backdoor used for persistent access and command-and-control in intrusions.
Malware capable of modifying file and directory timestamps.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.