FALLCHILL
MITRE ATT&CK: S0181 View on attack.mitre.org
Aliases: FALLCHILL
- First seen
- 2016-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 15:47:02
Targeted industries: defense-and-aerospace technology-and-telecommunications financial-services
Context
FALLCHILL is a RAT that has been used by Lazarus Group since at least 2016 to target the aerospace, telecommunications, and finance industries. It is usually dropped by other Lazarus Group malware or delivered when a victim unknowingly visits a compromised website.
Detection coverage
- 120 Sigma rules
Malware & tools used
- File and Directory Discovery (attack-pattern)
- Timestomp (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- File Deletion (attack-pattern)
- System Information Discovery (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Local Storage Discovery (attack-pattern)
- Windows Service (attack-pattern)
- Protocol or Service Impersonation (attack-pattern)
Used by threat actors
- Lazarus Group (threat-actor)
Related threat objects
- Volgmer (malware)
Reports & references
- us-cert.gov — Ta17 318A (report)
- Kaspersky — 87553 (report)
- MITRE ATT&CK — S0181 (report)