Valak

Malware updated 4 months ago (2024-05-04T20:18:20.002Z)
Download STIX
Preview STIX
Valak is a type of malware, or malicious software, that infiltrates systems to exploit and damage them. It was distributed by threat actor TA551, which has historically pushed various families of information-stealing malware such as Ursnif and IcedID. Valak, in particular, is known as a malware downloader, often followed up by further infections like IcedID. The malware was active since 2016, initially disseminated by Hive0106, another threat group, alongside other payloads like IcedID and QakBot. On December 19, 2019, there was an instance where a Windows host infected with Ursnif by TA551 also contracted IcedID and Valak as follow-up malware. This marked a significant event in the proliferation of Valak. TA551 continued to distribute Valak until early July 2020. During this period, the English-speaking recipients were the primary targets, and IcedID was frequently observed as follow-up malware from these infections. TA551's strategy evolved over time, with a noted shift in its approach to deploying malware. By mid-to-late July 2021, the group had shifted away from using malware downloaders like Valak and Ursnif and began directly deploying IcedID. This evolution in tactics signifies a critical change in the threat landscape, marking the end of the deployment of Valak by TA551.
Description last updated: 2024-05-04T19:26:06.999Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Valak Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
MITRE
9 months ago
Trickbot Rising — Gang Doubles Down on Infection Efforts to Amass Network Footholds
MITRE
2 years ago
TA551: Email Attack Campaign Switches from Valak to IcedID
MITRE
2 years ago
Evolution of Valak, from Its Beginnings to Mass Distribution
MITRE
2 years ago
Cybereason vs. WhisperGate and HermeticWiper
CERT-EU
2 years ago
South American Cyberspies Impersonate Colombian Government in Recent Campaign