Valefor is a custom remote access trojan (RAT) / implant associated with the North Korean threat activity tracked as Andariel, also known as Onyx Sleet and other aliases, and also referenced in reporting on the subgroup NICKEL HYATT. The provided content identifies it as one of the RATs developed and used by this DPRK-linked cluster over many years, and also refers to it as Valefor/VSingle. In the cited FBI-led July 2024 advisory on Andariel activity, Valefor/VSingle is listed among the group’s custom malware used in cyber espionage operations. The advisory describes the broader malware set as supporting capabilities including arbitrary command execution, keylogging, screenshots, file and directory listing, browser history retrieval, process snooping, and uploading content to command-and-control infrastructure, with each implant typically using a designated C2 node to maintain access. The malware is associated with campaigns targeting defense, aerospace, nuclear, and engineering organizations for sensitive military and technical information, with additional targeting of medical and energy sectors. The same actor set is described as gaining initial access primarily through exploitation of public-facing applications and known vulnerabilities, followed by web shell deployment, persistence via Scheduled Tasks, credential theft, lateral movement, tunneling/proxy use, and exfiltration via cloud services or tools such as PuTTY and WinSCP. Separate reporting in the content also states that NICKEL HYATT, a North Korea-linked subgroup associated with Andariel, has used custom malware such as Rifle/Rifdoor, Valefor, UnitBot, and DTrack in espionage and financially motivated operations across South Korea, Japan, the United States, and India. No Valefor-specific indicators of compromise are directly provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Over the last 15 years, the group has developed RATs, including the following... ▪ Valefor/VSingle
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Over the last 15 years, the group has developed RATs, including the following... ▪ Valefor/VSingle
"...custom malware such as Rifle (also known as Rifdoor), Valefor, UnitBot, and DTrack..."
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.