Skip to content

Malware

Fire Chili

The purpose of this rootkit/driver is hiding and protecting malicious artifacts from user-mode components(e.g.

Fire Chili is a Windows malware family operated by Shell Crew.

Background

This rootkit/driver is designed to conceal and shield malicious artifacts—such as files, processes, registry keys, and network connections—from user-mode components. Fortguard Labs notes that it relies on Direct Kernel Object Modification (DKOM), which manipulates undocumented kernel structures and objects, and as a consequence the malware is dependent on specific OS builds.


Source: Malpedia (Fraunhofer FKIE).