Valak
MITRE ATT&CK: S0476 View on attack.mitre.org
Aliases: Valek, Valak
- First seen
- 2019-01-01 00:00:00
- Malware type
- downloader, credential-stealer
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 2 (2 malicious)
- Last IoC activity
- 2026-08-08 18:57:16
- Profile updated
- 2026-07-07 12:59:51
Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical
Targeted regions: country_code:us country_code:de
Context
Valak is a multi-stage modular malware that can function as a standalone information stealer or downloader, first observed in 2019 targeting enterprises in the US and Germany.
Recent IoC activity
2 malicious indicators in Maltiverse are attributed to Valak (S0476). The 2 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | scenario_vlk04820sdkaemr3___d725afa4-381b-48a0-a5dd-d82585b7bc18.0 | 2026-08-08 | 1 |
| file sample | files_06.20.doc | 2026-03-21 | 1 |
Detection coverage
- 804 Sigma rules
Malware & tools used
- Modify Registry (attack-pattern)
- Windows Credential Manager (attack-pattern)
- Process Discovery (attack-pattern)
- NTFS File Attributes (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Regsvr32 (attack-pattern)
- Web Protocols (attack-pattern)
- Multi-Stage Channels (attack-pattern)
- Fallback Channels (attack-pattern)
- Security Software Discovery (attack-pattern)
- Malicious File (attack-pattern)
- Screen Capture (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Dynamic Data Exchange (attack-pattern)
- JavaScript (attack-pattern)
- System Information Discovery (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Automated Collection (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Credentials in Registry (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Remote Email Collection (attack-pattern)
- Software Packing (attack-pattern)
- Fileless Storage (attack-pattern)
Used by threat actors
- TA551 (threat-actor)
Reports & references
- Palo Alto Unit 42 — Monsterlibra (report)
- Palo Alto Unit 42 — Valak Evolution (report)
- securityintelligence.com — Sodinokibi Ransomware Incident Response Intelligence Together (report)
- malpedia.caad.fkie.fraunhofer.de — Js.Valak (report)
- threatresearch.ext.hp.com — Detecting Ta551 Domains (report)
- cybereason.com — Valak More Than Meets The Eye (report)
- labs.sentinelone.com — Valak Malware And The Connection To Gozi Loader Confcrew (report)
- twitter.com — 1207824548021886977 (report)
- cocomelonc.github.io — Malware Tricks 35 (report)
- Cisco Talos — Valak Emerges (report)
- medium.com — Casual Analysis Of Valak C2 3497Fdb79Bf7 (report)
- security-soup.net — Analysis Of Valak Maldoc (report)
- MITRE ATT&CK — S0476 (report)