Valak

MITRE ATT&CK: S0476 View on attack.mitre.org

Aliases: Valek, Valak

First seen
2019-01-01 00:00:00
Malware type
downloader, credential-stealer
Family
Malware family
Operating systems
windows
Related IoCs
2 (2 malicious)
Last IoC activity
2026-08-08 18:57:16
Profile updated
2026-07-07 12:59:51

Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical

Targeted regions: country_code:us country_code:de

Context

Valak is a multi-stage modular malware that can function as a standalone information stealer or downloader, first observed in 2019 targeting enterprises in the US and Germany.

Recent IoC activity

2 malicious indicators in Maltiverse are attributed to Valak (S0476). The 2 most recently updated:

TypeIndicatorUpdatedSources
file sample scenario_vlk04820sdkaemr3___d725afa4-381b-48a0-a5dd-d82585b7bc18.0 2026-08-08 1
file sample files_06.20.doc 2026-03-21 1

Detection coverage

  • 804 Sigma rules

Malware & tools used

  • Modify Registry (attack-pattern)
  • Windows Credential Manager (attack-pattern)
  • Process Discovery (attack-pattern)
  • NTFS File Attributes (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Regsvr32 (attack-pattern)
  • Web Protocols (attack-pattern)
  • Multi-Stage Channels (attack-pattern)
  • Fallback Channels (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Malicious File (attack-pattern)
  • Screen Capture (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Dynamic Data Exchange (attack-pattern)
  • JavaScript (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Automated Collection (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Credentials in Registry (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Remote Email Collection (attack-pattern)
  • Software Packing (attack-pattern)
  • Fileless Storage (attack-pattern)

Used by threat actors

Reports & references

  • Palo Alto Unit 42 — Monsterlibra (report)
  • Palo Alto Unit 42 — Valak Evolution (report)
  • securityintelligence.com — Sodinokibi Ransomware Incident Response Intelligence Together (report)
  • malpedia.caad.fkie.fraunhofer.de — Js.Valak (report)
  • threatresearch.ext.hp.com — Detecting Ta551 Domains (report)
  • cybereason.com — Valak More Than Meets The Eye (report)
  • labs.sentinelone.com — Valak Malware And The Connection To Gozi Loader Confcrew (report)
  • twitter.com — 1207824548021886977 (report)
  • cocomelonc.github.io — Malware Tricks 35 (report)
  • Cisco Talos — Valak Emerges (report)
  • medium.com — Casual Analysis Of Valak C2 3497Fdb79Bf7 (report)
  • security-soup.net — Analysis Of Valak Maldoc (report)
  • MITRE ATT&CK — S0476 (report)

External references