/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

US CERT identifies FALLCHILL RAT used by North Korean Lazarus Group, sources say in use since 2016; US also shared IP addresses associated with Volgmer trojan

HIDDEN COBRA - North Korean Trojan: Volgmer Patrick Howell O'Neill / Cyberscoop : U.S. CERT issues report on remote hacking tool used by North Korea Stephanie Condon / ZDNet : DHS, FBI describe North Korea's use of FALLCHILL malware The Guardian : North Korea-developed malware is still on US networks, officials warn Shona Ghosh / Business Insider : 10 things in tech you need to know today Tweets: Carl Franzen / @carlfranzen : Big but barely covered news here: US says North Korea hackers targeted aerospace industry with malware known as Fallchill http://www.reuters.com/... http://twitter.com/... Eric Geller / @ericgeller : DHS also posted information about a remote access tool used by the North Korean hackers, dubbed FALLCHILL. http://www.us-cert.gov/... http://twitter.com/...

SecurityWeek Mike Lennon

Context & Ripple Effects

This is the first time US CERT has publicly pinned specific malware families to the Lazarus Group's operations: the FBI and DHS would later expand this into a nine-year accounting of North Korean intrusions hitting infrastructure, aerospace, financial, and media targets. By publishing FALLCHILL indicators alongside Volgmer IP addresses, DHS and FBI are doing for North Korea what they had already begun doing for Russia, where the NSA and FBI disclosed Fancy Bear's previously undisclosed Drovorub Linux implant.

The disclosure matters because officials say the malware is still active on US networks six years after it first appeared, and because the aerospace industry is the named target. The playbook has held up: Cisco Talos reported in 2023 that [[a:843502|Lazarus was still rotating new malware variants against internet backbone and healthcare targets]], showing the group treats each public exposure as a cue to retool rather than retreat.

First-order effects

  • Network defenders at aerospace firms and other US organizations can now sweep their environments for FALLCHILL and block the published Volgmer IP addresses, turning a classified-grade attribution into actionable detection rules overnight.

Second-order effects

  • Lazarus operators lose infrastructure and must migrate command-and-control, accelerating the variant churn that Cisco Talos documented years later when the group resurfaced against backbone and healthcare networks.

Third-order effects

  • Joint DHS-FBI technical advisories become the standard instrument for countering state hackers — a model repeated against Russian and Chinese actors — shifting defense from reactive incident response to government-published threat hunting.

The trend: Governments are responding to persistent state-sponsored malware by publishing indicators and attribution directly to defenders, turning each disclosure into both a defensive tool and a signal that adversaries like Lazarus will answer with new variants.