ValueVault is a Windows credential-theft tool associated with the Iranian state-aligned threat actor APT34, also known as OilRig. It has been used in espionage operations targeting organizations in sectors such as government, energy, utilities, and oil and gas, particularly in the Middle East. The malware is designed to extract and display credentials stored in the Windows Vault, and reporting also links it to password dumping activity against browser-stored credentials. At least one observed sample was compiled in Go and derived from publicly available Windows Vault password-dumping code. ValueVault has been observed alongside other APT34 tooling including Pickpocket, Longwatch, and TONEDEAF in phishing-led intrusion activity. Its role within those operations is credential access and post-compromise collection rather than destructive action or monetization.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In this phishing campaign, three new malware families were detected, named as Pickpocket, ValueVault, and Longwatch. ... ValueVault - It is used to extract and view the credentials stored in the Windows Vault.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Most recently in June 2019, a phishing campaign was observed asking victims to join their social network. This time the group masqueraded as a Cambridge University lecturer, also setting up a LinkedIn page in order to gain victims’ trust.
They use phishing emails to deliver weaponized Microsoft Excel documents... Between 2014 to 2016, the group's attack campaigns targeted banks and technology organizations in Saudi Arabia with phishing emails that included weaponized Microsoft Excel attachments.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A credential theft tool used to extract and view credentials stored in Windows Vault.
Golang-based credential theft utility used by APT34 to dump credentials from Windows Vault; also invokes PowerShell to extract browser history to help correlate passwords with visited sites. Writes output into a SQLite DB (fsociety.dat) and lacks built-in network exfiltration per the report.
Tool used to dump passwords from web browsers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.