Skip to content

Malware

FULLHOUSE

Fullhouse (AKA FULLHOUSE.DOORED) is a custom backdoor used by subsets of the North Korean Lazarus Group.

FULLHOUSE is a macOS malware family.

Background

Fullhouse (AKA FULLHOUSE.DOORED) is a tailor-made backdoor employed by elements of the North Korean Lazarus Group. Coded in C/C++, it functions as a tunneler and supports backdoor operations such as shell command execution, file transfer, file management, and process injection. It communicates with its C2 over HTTP, with settings supplied either via the command line or a configuration file.


Source: Malpedia (Fraunhofer FKIE).