Trifaux is a custom remote access trojan (RAT) associated with the DPRK Reconnaissance General Bureau (RGB) 3rd Bureau threat group Andariel, also tracked as Onyx Sleet and formerly PLUTONIUM, DarkSeoul, Silent Chollima, and Stonefly/Clasiopa. It is listed in a joint FBI-led Cybersecurity Advisory (AA24-207A, July 25, 2024) as one of multiple Andariel-developed RATs and implants. The advisory places Trifaux within Andariel’s broader cyber espionage and ransomware operations targeting defense, aerospace, nuclear, and engineering organizations for sensitive military information and intellectual property, with additional targeting of medical and energy sectors.
Within the advisory, Trifaux is grouped with Andariel malware used after initial compromise. The actors commonly gain access by exploiting public-facing web servers using known vulnerabilities, including CVE-2021-44228 (Log4Shell), then deploy web shells, establish persistence via Scheduled Tasks, steal credentials using tools such as Mimikatz, and move laterally using SMB, RDP, and built-in system tools. The advisory states Andariel-developed RATs and implants, including Trifaux, support capabilities such as arbitrary command execution, keylogging, screenshots, file and directory listing, browser history retrieval, process snooping, and uploading content to command-and-control infrastructure. Each implant typically has a designated C2 node to maintain access.
The advisory also notes Andariel often disguises command and control within HTTP traffic, uses proxy and tunneling tools such as 3Proxy, PLINK, and Stunnel, and routinely packs late-stage tooling with VMProtect and Themida for anti-debugging and evasion. Trifaux is explicitly referenced in detection content via the YARA rule name "TriFaux_EasyRAT_JUPITER." No Trifaux-specific hashes or standalone infection vector details are provided in the supplied content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Over the last 15 years, the group has developed RATs, including the following... ▪ Trifaux
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
1 distinct technique documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.