Digital Edge team was tasked to help contain and eradicate a virus outbreak. A response team was gathered and after the initial kick-off call, the team started cleaning/investigation activities.
The Digital Edge Security Team warns that HIDDEN COBRA actors have been using FALLCHILL malware to target IT infrastructures. DHS and FBI specified Internet Protocol (IP) addresses and other indicators of compromise (IOCs) associated with a remote administration tool (RAT) used by the North Korean government—commonly known as FALLCHILL. The U.S. Government refers to malicious cyber activity by North Korea as HIDDEN COBRA.
HIDDEN COBRA uses dual proxy technique allowing to change vector of the attack and keep the source of the attack hidden.
These types of activities can have severe impacts such as data loss and disruption of operation. The Digital Edge Security Team has updated its own core infrastructure to protect our clients from possible impacts of HIDDEN COBRA and advise other IT organization to use the same practice.