Preft is a multi-stage backdoor/RAT associated with the North Korea-linked Stonefly threat group, also tracked as Andariel, APT45, Silent Chollima, and Onyx Sleet. In the provided reporting, it is described as Backdoor.Preft and also known as Dtrack and Valefor/VSingle. Symantec states Backdoor.Preft is exclusively associated with Stonefly and observed it in several financially motivated intrusions against U.S. private companies in August 2024. Preft supports file upload and download, command execution, and downloading additional plugins, including executable files, VBS, BAT, and shellcode. Reported persistence mechanisms include Startup_LNK, Service, Registry, and Task Scheduler. Broader government reporting on the same actor cluster links this malware family to campaigns involving exploitation of public-facing web servers, web shell deployment, credential theft, lateral movement, tunneling/proxy tooling, and exfiltration to cloud services or remote servers. The associated actor set primarily targets defense, aerospace, nuclear, and engineering organizations for espionage, with additional targeting of medical and energy sectors, and has also conducted ransomware operations against U.S. healthcare entities. High-confidence related activity in the provided content includes use of Mimikatz, WDigest registry modification for plaintext credential capture, keylogging, and dual-use tools such as Sliver, Chisel, FRP, PuTTY/Plink, Snap2HTML, Megatools, and WinSCP/PuTTY for exfiltration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Over the last 15 years, the group has developed RATs, including the following... ▪ Preft
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
1 distinct technique documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Multi-stage backdoor used for remote access: can download/upload files, execute commands, and fetch additional plugins (EXE, VBS, BAT, shellcode). Supports multiple persistence mechanisms (Startup LNK, service, registry, scheduled task).
Custom malware/implant used by the group for access and operations (specific functionality not detailed in the advisory).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.