FALLCHILL is a North Korean remote access trojan associated with Lazarus Group activity, including operations tracked by the U.S. government as HIDDEN COBRA. It has been used as a full-function RAT for post-compromise control of Windows systems and has appeared in campaigns linked to espionage and financially motivated intrusions, including activity targeting cryptocurrency-related organizations through the AppleJeus ecosystem.
FALLCHILL supports encrypted command-and-control communications, including RC4-protected traffic, and has also been described as using fake TLS-style network communications to blend malicious traffic with legitimate encrypted sessions. On infected hosts it can collect local network configuration details such as MAC address and local IP address information, providing basic host and network reconnaissance to operators.
The malware includes multiple defense-evasion and cleanup features. It has been observed installing itself as a Windows service for persistence, modifying file or directory timestamps to hinder forensic analysis, and deleting malware components and associated artifacts from victim systems to reduce evidence of compromise. These behaviors align with long-observed Lazarus tradecraft emphasizing durable access, operational security, and anti-forensics.
FALLCHILL is best characterized as a Windows RAT used after initial access to maintain control, gather host information, and support broader intrusion objectives. It is part of the broader Lazarus malware ecosystem alongside other DPRK-linked implants and has remained a recognized malware family in ATT&CK and government reporting for years.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This incident led to the victim company being infected with the malware known to the U.S. Government as FALLCHILL, a North Korean remote administration tool (RAT).
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The cybersecurity company that published the report states the payload was an encrypted and obfuscated binary ( Obfuscated Files or Information [T1027])... The program CrashReporter.exe is heavily obfuscated...
Examples throughout the content include deleting tools, logs, malware-related files, staged archives, screenshots, temporary files, and exfiltrated data 'to cover their tracks,' 'reduce their footprint,' 'remove traces of activity,' or as part of 'post-intrusion cleanup.'
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
Updater.exe ... collects the victim’s host information ( System Owner/User Discovery [T1033]), encrypts the collected information ... and sends information to a C2 website.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
sends the data to "celasllc.com/checkupdate.php." ... If the malware receives a response with HTTP code 200, it will decode the base64 payload
If the malware receives a response with HTTP code 200, it will decode the base64 payload, then decrypt the result using the hard-coded RC4 decryption key
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... FALLCHILL ... (v1.2→v1.3) ...
FALLCHILL (v1.2→v1.3)
Lazarus-associated backdoor used for persistent access and command-and-control in intrusions.
Malware capable of modifying file and directory timestamps.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.