FALLCHILL

MITRE ATT&CK: S0181 View on attack.mitre.org

Aliases: FALLCHILL

First seen
2016-01-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 15:47:02

Targeted industries: defense-and-aerospace technology-and-telecommunications financial-services

Context

FALLCHILL is a RAT that has been used by Lazarus Group since at least 2016 to target the aerospace, telecommunications, and finance industries. It is usually dropped by other Lazarus Group malware or delivered when a victim unknowingly visits a compromised website.

Detection coverage

  • 120 Sigma rules

Malware & tools used

  • File and Directory Discovery (attack-pattern)
  • Timestomp (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • File Deletion (attack-pattern)
  • System Information Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Local Storage Discovery (attack-pattern)
  • Windows Service (attack-pattern)
  • Protocol or Service Impersonation (attack-pattern)

Used by threat actors

Related threat objects

Reports & references

  • us-cert.gov — Ta17 318A (report)
  • Kaspersky — 87553 (report)
  • MITRE ATT&CK — S0181 (report)

External references