FULLHOUSE
- First seen
- 2020-05-15 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Profile updated
- 2026-07-07 13:07:45
Targeted industries: government-and-public-sector financial-services energy-and-utilities
Targeted regions: country_code:us country_code:kr country_code:jp
Context
Fullhouse (AKA FULLHOUSE.DOORED) is a custom backdoor used by subsets of the North Korean Lazarus Group. Fullhouse is written in C/C++ and includes the capabilities of a tunneler and backdoor commands support such as shell command execution, file transfer, file managment, and process injection. C2 communications occur via HTTP and require configuration through the command line or a configuration file.
Reports & references
- Mandiant — North Korea Supply Chain (report)
- malpedia.caad.fkie.fraunhofer.de — Osx.Fullhouse (report)