Fire Chili
- Malware type
- rootkit
- Family
- Malware family
- Profile updated
- 2026-07-07 15:01:33
Targeted industries: technology-and-telecommunications government-and-public-sector financial-services
Context
The purpose of this rootkit/driver is hiding and protecting malicious artifacts from user-mode components(e.g. files, processes, registry keys and network connections). According to Fortguard Labs, this malware uses Direct Kernel Object Modification (DKOM), which involves undocumented kernel structures and objects, for its operations, why this malware has to rely on specific OS builds.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Firechili (report)
- thehackernews.com — Chinese Hackers Target Vmware Horizon (report)
- fortinet.com — Deep Panda Log4Shell Fire Chili Rootkits (report)