FALLCHILL is a North Korean remote administration tool associated with Lazarus Group, also referred to by the U.S. government as HIDDEN COBRA. It is a full-function Windows RAT used to maintain access to compromised systems and execute a broad range of operator commands. Reported capabilities include host reconnaissance such as collecting MAC and local IP address information, encrypted command-and-control communications using RC4, anti-forensic cleanup through deletion of malware and related artifacts, and defense evasion through modification of file or directory timestamps. FALLCHILL has also been observed using fake TLS-style network communications to disguise command-and-control traffic and has been installed as a Windows service for persistence. The malware has been linked to campaigns targeting cryptocurrency-related organizations and financial entities, including activity in which trojanized cryptocurrency trading applications ultimately delivered FALLCHILL as a later-stage payload. It is part of the broader Lazarus malware ecosystem used in espionage and financially motivated operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The second tool is a Remote Administration Tool (RAT) labeled FALLCHILL. This RAT is fully functional and able to issue a wide variety of commands from a C2 server to the victim’s device.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The cybersecurity company that published the report states the payload was an encrypted and obfuscated binary ( Obfuscated Files or Information [T1027])... The program CrashReporter.exe is heavily obfuscated...
Examples throughout the content include deleting tools, logs, malware-related files, staged archives, screenshots, temporary files, and exfiltrated data 'to cover their tracks,' 'reduce their footprint,' 'remove traces of activity,' or as part of 'post-intrusion cleanup.'
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
Updater.exe ... collects the victim’s host information ( System Owner/User Discovery [T1033]), encrypts the collected information ... and sends information to a C2 website.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
FALLCHILL ... is fully functional and able to issue a wide variety of commands from a C2 server to the victim’s device.
sends the data to "celasllc.com/checkupdate.php." ... If the malware receives a response with HTTP code 200, it will decode the base64 payload
If the malware receives a response with HTTP code 200, it will decode the base64 payload, then decrypt the result using the hard-coded RC4 decryption key
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... FALLCHILL ... (v1.2→v1.3) ...
FALLCHILL (v1.2→v1.3)
Lazarus-associated backdoor used for persistent access and command-and-control in intrusions.
Malware capable of modifying file and directory timestamps.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.