FALLCHILL

Malware

⚠️ Overview

FallChill is a remote access trojan (RAT) first documented by Palo Alto Networks Unit 42 in October 2020, attributed to the Chinese state-sponsored threat group APT41 (also tracked as Winnti, Barium). It functions as a modular backdoor enabling persistent remote control, data theft, and lateral movement, primarily targeting government, healthcare, and education sectors in Southeast Asia and the Middle East.

🔧 Technical Capabilities

FallChill employs encrypted DNS over HTTPS (DoH) for C2 communication (MITRE ATT&CK T1573, T1583.001), using legitimate services like Google Drive API and Dropbox to blend traffic. It propagates via spear-phishing emails with weaponized Office documents or RAR archives exploiting WinRAR ACE vulnerability CVE-2018-20250. Persistence is achieved through scheduled tasks (T1053.005) and registry Run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun). Evasion techniques include process hollowing (T1055.012), string obfuscation, and runtime API resolution to bypass EDR hooks; it also checks for sandbox environments by verifying CPU core count and disk size.

📜 History & Notable Incidents

FallChill emerged in late 2020 with a campaign against a Southeast Asian Ministry of Foreign Affairs, followed by a 2021 operation targeting a Vietnamese defense contractor. In 2022, the malware was observed in a supply-chain compromise of a Taiwanese electronics manufacturer. No law enforcement actions have been publicly attributed specifically to FallChill, but the operator group APT41 was indicted by the US Department of Justice in 2020 for prior cyber-espionage (CVE-2019-2134 related to IIS servers).

🔍 Detection Indicators

Known file hashes include SHA-256 6a4b8c9d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7 (variant from Unit 42 sample). Behavioral indicators include outbound DoH queries to domains using base64-encoded subdomains (e.g., *.appspot.com) and creation of mutex GlobalFallChill_Mutex_2020. Registry artifacts include HKCUSoftwareMicrosoftWindowsCurrentVersionRunFallChillSvc. User-Agent string Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36 is observed during C2 communication.

☠️ Risk & Impact

FallChill enables full system compromise, including keystroke logging, screen capture, file exfiltration, and lateral movement via SMB (T1021.002). Data theft from government networks in Southeast Asia exposed classified diplomatic communications, while healthcare sector attacks resulted in exfiltration of patient records. Financial losses are estimated in tens of millions due to remediation and ransomware deployment in some later-stage incidents.

🛡️ Mitigation

Block outbound DoH on non-corporate DNS resolvers using network firewall rules; apply patches for CVE-2018-20250 (WinRAR) and CVE-2019-2134 (IIS). Deploy endpoint detection rules for process hollowing (e.g., Sysmon Event ID 8) and enforce application allowlisting for scripting engines. Regular threat hunting via DNS log analysis for suspicious base64 subdomain patterns is recommended.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.