
| Names | VSingle | |
| Category | Malware | |
| Type | Backdoor, Downloader, Loader | |
| Description | (JPCERT/CC) VSingle is a HTTP bot which executes arbitrary code from a remote network. It also downloads and executes plugins. Once launched, this malware runs Explorer and executes its main code through DLL injection. | |
| Information | <https://blogs.jpcert.or.jp/en/2021/03/Lazarus_malware3.html> | |
| Malpedia | <https://malpedia.caad.fkie.fraunhofer.de/details/win.vsingle> | |
Last change to this tool card: 27 December 2022
Download this tool card in JSON format
| Changed | Name | Country | Observed | ||
APT groups | |||||
| Lazarus Group, Hidden Cobra, Labyrinth Chollima | 2007-May 2025 | ![]() | |||
1 group listed (1 APT, 0 other, 0 unknown)
|
Digital Service Security Center Follow us on |
Report incidents |
|
| +66 (0)2-123-1227 | ||
| [email protected] | ||