Malware.View on attack.mitre.org
Valak is a multi-stage modular malware that can function as a standalone information stealer or downloader, first observed in 2019 targeting enterprises in the US and Germany.
| Technique | Procedure example |
|---|---|
| T1008 Fallback Channels |
Valak can communicate over multiple C2 hosts. |
| T1012 Query Registry |
Valak can use the Registry for code updates and to collect credentials. |
| T1016 System Network Configuration Discovery |
Valak has the ability to identify the domain and the MAC and IP addresses of an infected machine. |
| T1027 Obfuscated Files or Information |
Valak has the ability to base64 encode and XOR encrypt strings. |
| T1027.002 Software Packing |
Valak has used packed DLL payloads. |
| T1027.011 Fileless Storage |
Valak has the ability to store information regarding the C2 server and downloads in the Registry key |
| T1033 System Owner/User Discovery |
Valak can gather information regarding the user. |
| T1041 Exfiltration Over C2 Channel |
Valak has the ability to exfiltrate data over the C2 channel. |
| T1047 Windows Management Instrumentation |
Valak can use |
| T1053.005 Scheduled Task |
Valak has used scheduled tasks to execute additional payloads and to gain persistence on a compromised host. |
| T1057 Process Discovery |
Valak has the ability to enumerate running processes on a compromised host. |
| T1059.001 PowerShell |
Valak has used PowerShell to download additional modules. |
| T1059.007 JavaScript |
Valak can execute JavaScript containing configuration data for establishing persistence. |
| T1071.001 Web Protocols |
Valak has used HTTP in communications with C2. |
| T1082 System Information Discovery |
Valak can determine the Windows version and computer name on a compromised host. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.