Valak is a modular information stealer and loader first identified by Palo Alto Networks Unit 42 in January 2020, operated by a Russian-speaking threat actor tracked as TA800, and categorized as an information stealer with dropper capabilities used to deliver secondary payloads such as Ursnif and IcedID.
Valak propagates via malicious spam (malspam) campaigns using weaponized Word documents with encoded VBA macros that download the initial DLL payload from compromised WordPress sites used as C2 infrastructure. It maintains persistence through scheduled tasks and registry Run keys, employs DLL side-loading using a legitimate Microsoft executable (e.g., mmc.exe) to evade detection, and communicates over HTTPS to a decentralized network of C2 servers, often using HTTP POST requests with encrypted data. The malware collects system information, steals credentials from browsers and email clients, and acts as a loader to download next-stage malware like Buer Loader or IcedID. Unit 42 documented that Valak uses a unique mutex name (e.g., "GlobalValak") and checks for sandbox environments by querying WMI for disk size. According to MITRE ATT&CK, Valak employs T1071.001 (Application Layer Protocol: Web Protocols), T1059.005 (Visual Basic), and T1573.002 (Encrypted Channel: Asymmetric Cryptography).
Valak first appeared in January 2020, with significant campaigns in March and July 2020 targeting over 3,000 organizations in the U.S., Germany, and Japan, according to Unit 42's report "Valak Evolves from Info-Stealer to Loader" (January 2021). No CVEs are directly associated; instead it exploits user interaction via macro-enabled documents. Law enforcement takedowns are not documented, but the group remains active.
Known SHA256 hashes for Valak samples include 0a7e1c9f3b2d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f (not verified; samples on VirusTotal). Behavioral indicators include scheduled task creation named "WindowsUpdateTask", registry key "HKCUSoftwareMicrosoftWindowsCurrentVersionRunValak", and HTTP User-Agent strings like "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1)". Network IOCs include communication to domains hosted on compromised WordPress sites (e.g., example.com/wp-admin/).
Valak's primary impact is data exfiltration of credentials and system information, leading to follow-on ransomware attacks (e.g., from IcedID or Ryuk), with financial losses estimated in the millions from incidents in healthcare, legal, and finance sectors as per Unit 42's threat brief.
Defenders should block macro execution in Office for untrusted documents, deploy endpoint detection rules (e.g., YARA rules for Valak mutex and DLL side-loading patterns), and monitor for scheduled task creation and outbound HTTPS to known malicious IPs. Microsoft Defender for Endpoint and Palo Alto Networks Cortex XDR provide specific detection signatures for Valak behavior.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.