ValidAlpha is a remote access trojan (RAT)/implant associated with the DPRK Reconnaissance General Bureau (RGB) 3rd Bureau threat group Andariel, also tracked as Onyx Sleet and formerly as PLUTONIUM, DarkSeoul, Silent Chollima, and Stonefly/Clasiopa. In the cited FBI-led joint Cybersecurity Advisory, ValidAlpha is listed as one of multiple Andariel-developed RATs and implants used in the group’s cyber espionage and ransomware operations. The advisory attributes these operations to a long-running campaign targeting primarily defense, aerospace, nuclear, and engineering organizations for sensitive military information and intellectual property, with additional targeting of medical and energy sectors. Reported initial access methods for the broader Andariel intrusion set include exploitation of public-facing web servers and known vulnerabilities such as Log4Shell (CVE-2021-44228), deployment of web shells, and phishing with malicious ZIP archives containing Windows LNK files or HTA scripts. The advisory states Andariel establishes persistence via Scheduled Tasks, steals credentials with tools such as Mimikatz, moves laterally with SMB and RDP, and exfiltrates data via cloud services or tools such as PuTTY and WinSCP. Across Andariel-developed RATs and implants, documented capabilities include arbitrary command execution, keylogging, screenshots, file and directory listing, browser history retrieval, process snooping, and uploading content to command-and-control infrastructure; each implant typically has a designated C2 node to maintain access. The advisory also notes the group commonly uses living-off-the-land tools, proxy/tunneling utilities, and packs late-stage tooling with VMProtect and Themida. No ValidAlpha-specific indicators of compromise or unique technical behaviors beyond its inclusion in the Andariel malware set are directly provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Over the last 15 years, the group has developed RATs, including the following... ▪ ValidAlpha
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
1 distinct technique documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.