FULLHOUSE

First seen
2020-05-15 00:00:00
Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 13:07:45

Targeted industries: government-and-public-sector financial-services energy-and-utilities

Targeted regions: country_code:us country_code:kr country_code:jp

Context

Fullhouse (AKA FULLHOUSE.DOORED) is a custom backdoor used by subsets of the North Korean Lazarus Group. Fullhouse is written in C/C++ and includes the capabilities of a tunneler and backdoor commands support such as shell command execution, file transfer, file managment, and process injection. C2 communications occur via HTTP and require configuration through the command line or a configuration file.

Reports & references

  • Mandiant — North Korea Supply Chain (report)
  • malpedia.caad.fkie.fraunhofer.de — Osx.Fullhouse (report)

External references