FALLCHILL

FALLCHILLFALLCHILL

Description

According to trusted third-party reporting, HIDDEN COBRA actors have likely been using FALLCHILL malware since 2016 to target the aerospace, telecommunications, and finance industries. The malware is a fully functional RAT with multiple commands that the actors can issue from a command and control (C2) server to a victim’s system via dual proxies. FALLCHILL typically infects a system as a file dropped by other HIDDEN COBRA malware or as a file downloaded unknowingly by users when visiting sites compromised by HIDDEN COBRA actors. HIDDEN COBRA actors use an external tool or dropper to install the FALLCHILL malware-as-a-service to establish persistence. Because of this, additional HIDDEN COBRA malware may be present on systems compromised with FALLCHILL.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
COLDCAT
Software
GravityRAT
Software
GovRAT
Software
Raindrop
Software
SLOWDRIFT
Software
Volgmer
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.