ATT&CKReferencesUnit 42 Valak July 2020

Unit 42 Valak July 2020

Duncan, B. (2020, July 24). Evolution of Valak, from Its Beginnings to Mass Distribution. Retrieved August 31, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareValak

Valak can communicate over multiple C2 hosts.

T1012
Query Registry
MalwareValak

Valak can use the Registry for code updates and to collect credentials.

T1027
Obfuscated Files or Information
MalwareValak

Valak has the ability to base64 encode and XOR encrypt strings.

T1027.010
Command Obfuscation
GroupTA551

TA551 has used obfuscated variable names in a JavaScript configuration file.

T1027.011
Fileless Storage
MalwareValak

Valak has the ability to store information regarding the C2 server and downloads in the Registry key HKCU\Software\ApplicationContainer\Appsw64.

T1041
Exfiltration Over C2 Channel
MalwareValak

Valak has the ability to exfiltrate data over the C2 channel.

T1053.005
Scheduled Task
MalwareValak

Valak has used scheduled tasks to execute additional payloads and to gain persistence on a compromised host.

T1071.001
Web Protocols
GroupTA551

TA551 has used HTTP for C2 communications.

T1071.001
Web Protocols
MalwareValak

Valak has used HTTP in communications with C2.

T1104
Multi-Stage Channels
MalwareValak

Valak can download additional modules and malware capable of using separate C2 channels.

T1105
Ingress Tool Transfer
MalwareValak

Valak has downloaded a variety of modules and payloads to the compromised host, including IcedID and NetSupport Manager RAT-based malware.

T1112
Modify Registry
MalwareValak

Valak has the ability to modify the Registry key HKCU\Software\ApplicationContainer\Appsw64 to store information regarding the C2 server and downloads.

T1132.001
Standard Encoding
MalwareValak

Valak has returned C2 data as encoded ASCII.

T1132.001
Standard Encoding
GroupTA551

TA551 has used encoded ASCII text for initial C2 communications.

T1140
Deobfuscate/Decode Files or Information
MalwareValak

Valak has the ability to decode and decrypt downloaded files.

T1204.002
Malicious File
MalwareValak

Valak has been executed via Microsoft Word documents containing malicious macros.

T1218.010
Regsvr32
MalwareValak

Valak has used regsvr32.exe to launch malicious DLLs.

T1218.010
Regsvr32
GroupTA551

TA551 has used regsvr32.exe to load malicious DLLs.

T1564.004
NTFS File Attributes
MalwareValak

Valak has the ability save and execute files as alternate data streams (ADS).

T1566.001
Spearphishing Attachment
GroupTA551

TA551 has sent spearphishing attachments with password protected ZIP files.

T1566.001
Spearphishing Attachment
MalwareValak

Valak has been delivered via spearphishing e-mails with password protected ZIP files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.