#VSingle

Malware/Tool

2021-03-22 • Lazarus Attack Activities Targeting Japan (VSingle/ValeforBeta)

VSingle is a custom remote-access Trojan developed and used by Lazarus. Cisco Talos observed it after exploitation of vulnerable VMware Horizon servers in 2022, when operators downloaded post-exploitation tooling from web servers and sought long-term access for espionage against energy and other organizations in Canada, the United States, and Japan. VSingle appeared alongside YamaBot and MagicRAT in the same campaign.

Tagged Reports

« Back