Valak is a multi-stage Windows malware family used as a modular loader and information-gathering implant. It has been associated with email-borne intrusion activity in which victims are targeted through spearphishing messages carrying password-protected archives and malicious Microsoft Word documents with macros. After execution, Valak uses script-based stages and PowerShell to retrieve additional modules, and it has also used regsvr32 to launch malicious DLL components.
Valak supports multiple post-compromise functions including host reconnaissance and surveillance. Documented capabilities include enumerating running processes, collecting user information, identifying the victim system’s domain and network characteristics, and taking screenshots. It can decode and decrypt downloaded content, communicate with multiple command-and-control servers, and return command-and-control data encoded as ASCII.
For persistence and stealth, Valak has used scheduled tasks and JavaScript-based components containing configuration data. It can store configuration related to command-and-control and downloads in the Windows Registry, and it is also capable of saving and executing files through NTFS alternate data streams as a defense-evasion measure. Valak has additionally been described as malware that hijacks email reply chains and embeds malicious links or attachments to further propagate infection. Overall, Valak is best characterized as a modular Windows loader with strong post-exploitation and defense-evasion functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Shathak has distributed a variety of malware, predominantly malware with information-stealing capabilities, such as Ursniff and Valak in 2020
Valak uses a multi-stage, script-based malware that hijacks email replies and embeds malicious URLs or attachments to infect devices with fileless scripts.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Emails are harvested and used in ‘Reply Chain Attacks’ to further spread the malware with a purpose-built plugin, ‘exchgrabber’. | Valak uses a multi-stage, script-based malware that hijacks email replies and embeds malicious URLs or attachments to infect devices with fileless scripts.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.' | The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory.
attempted to lure victims into enabling malicious macros within email attachments... prompted victims to accept macros... Word documents containing malicious macros.
has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails... has required user execution of a malicious MSI installer... has been executed through user installation of an executable disguised as a flash installer.
The emails reference an attached ZIP archive and provide a password that can be used to extract the contents of the archive. | Microsoft Word documents inside these ZIP archives are used to initiate the Valak infection. Most of the documents analyzed feature the use of similar decoy images... instructing them to enable macros.
APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload.
Adversaries may search the Registry on compromised systems for insecurely stored credentials... Example commands to find Registry keys related to password information: Local Machine Hive: reg query HKLM /f password /t REG_SZ /s Current User Hive: reg query HKCU /f password /t REG_SZ /s
The plugin names itself in its config section as an ‘exchgrabber’ or exchange grabber... it will enumerate credentials from the Credential Manager looking for one associated with Office. | we also discovered a new plugin called ‘clientgrabber’, which is primarily utilized for stealing email credentials from the registry.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
108 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware dropper described as evolving into a more advanced multi-stage modular malware.
Malware family mentioned as part of Shathak’s prior distribution history.
Loader that can gather information regarding the user.
Malware with a clientgrabber module used to steal email credentials from the Windows Registry.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.