Fire Chili

Malware type
rootkit
Family
Malware family
Profile updated
2026-07-07 15:01:33

Targeted industries: technology-and-telecommunications government-and-public-sector financial-services

Context

The purpose of this rootkit/driver is hiding and protecting malicious artifacts from user-mode components(e.g. files, processes, registry keys and network connections). According to Fortguard Labs, this malware uses Direct Kernel Object Modification (DKOM), which involves undocumented kernel structures and objects, for its operations, why this malware has to rely on specific OS builds.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Firechili (report)
  • thehackernews.com — Chinese Hackers Target Vmware Horizon (report)
  • fortinet.com — Deep Panda Log4Shell Fire Chili Rootkits (report)

External references