• About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Privacy Policy
  • Contact us
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • All events
  • Digital Magazine
  • GITEX GLOBAL
No Result
View All Result
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • All events
  • Digital Magazine
  • GITEX GLOBAL
No Result
View All Result
CXO Insight Middle East
No Result
View All Result

Cybereason Discovers New Malware Targeting Enterprises

by CXO Staff
May 31, 2020
in News

Cybereason's new research from its Nocturnus Research team is an investigation into a malware that is known for stealing information and siphoning data.

malware cybersecurity cybercrime

Cybereason has announced a new research from its Nocturnus Research team, titled Valak: More than Meets the Eye. The report is an investigation into a malware that is known for stealing information and siphoning data, targeting hundreds of enterprises in the United States and Germany.

The sophisticated malware, discovered in late 2019, collects and steals sensitive information from the Microsoft Exchange mail system, including credentials and the domain certificate and uses evasive techniques to avoid detection and has evolved from being a malware loader into an information stealer.

To date, more than 30 versions of the malware have been found, revealing tremendous improvements in a very short period of time. Valak contains a fileless stage in which it uses the registry to store different components, it collects user, machine, and network information from infected hosts, can check the geo-location of the victim’s machine and take screenshots of infected machines.

“Over the course of six months, Valak’s developers made tremendous progress and released more than 30 versions of the malware. Each time, they extended the malware’s capabilities and added evasive techniques to improve its stealth. Valak has at least six plugin components that enable attackers to obtain sensitive information from its victims. The threat actor behind Valak is collaborating with other criminals across the E-Crime ecosystem to create an even more dangerous piece of malware,” said Assaf Dahan, Senior Director, Head of Threat Research, Cybereason.

Other key findings from the report include

  • Targeting Enterprises: More recent versions of Valak target Microsoft Exchange servers to steal enterprise mailing information and passwords along with the enterprise certificate. This has the potential to access critical enterprise accounts, causing damage to organisations, brand degradation, and ultimately a loss of consumer trust.
  • Rich Modular Architecture: Valak’s basic capabilities are extended with a number of plugin components for reconnaissance and information stealing.
  • Fast Development Cycles: Valak has evolved from a loader to a sophisticated, multi-stage modular malware that collects plugins from its C2 server to expand its capabilities. The Cybereason Nocturnus team has observed over 30 different versions in about six months.
  • Designed for Stealth: Valak uses advanced evasive techniques like ADS and hiding components in the registry. In addition, over time the developers of Valak chose to abandon using PowerShell, which can be detected and prevented by modern security products.
Tags: Assaf DahancybercrimeCybereasonfeatured2malwareSecurityValak
ShareTweet

Related Posts

Covoro YouCloud unveils Agentic AI UAE E-Invoicing solution at Tax Technology Summit
Banking and Finance

Covoro YouCloud unveils Agentic AI UAE E-Invoicing solution at Tax Technology Summit

December 5, 2025

Covoro YouCloud, a strategic joint venture formed to accelerate digital tax transformation across the GCC, announced its participation as a...

EQUATE and Kyndryl extend partnership to strengthen global IT systems
Business

EQUATE and Kyndryl extend partnership to strengthen global IT systems

December 4, 2025

EQUATE Group announced the renewal and expansion of its five-year managed infrastructure services partnership with Kyndryl. The renewed agreement reinforces...

Discussion about this post

Latest Issue

Covoro YouCloud unveils Agentic AI UAE E-Invoicing solution at Tax Technology Summit

Covoro YouCloud unveils Agentic AI UAE E-Invoicing solution at Tax Technology Summit

December 5, 2025
EQUATE and Kyndryl extend partnership to strengthen global IT systems

EQUATE and Kyndryl extend partnership to strengthen global IT systems

December 4, 2025
CIS partners with Cequence & Astrix to help enterprises secure AI and Agentic systems

CIS partners with Cequence & Astrix to help enterprises secure AI and Agentic systems

December 4, 2025

The most trusted source of strategic intelligence for IT decision makers in the Middle East.

About

  • About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Contact Us

Policies

  • Privacy Policy
© 2025 – CXO Insight Middle East. All Rights Reserved.
Facebook-f X-twitter Linkedin
Separated they live in Bookmarksgrove right at the coast of the Semantics, a large language ocean. A small river named Duden.

About

  • About Us
  • Site Map
  • Contact Us
  • Career

Policies

  • Help Center
  • Privacy Policy
  • Cookie Setting
  • Term Of Use

Join Our Newsletter

© 2024 – CXO Insight Middle East. All Rights Reserved.

Facebook-f Twitter Youtube Instagram

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Join our mailing list
Sign up here to get the latest news, updates and special offers delivered directly to your inbox.
No Result
View All Result
  • News
  • Opinions
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
  • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CX50 Oman
    • CXO50
    • ICT Awards
      • Dubai
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • All events
  • Videos
  • GITEX GLOBAL
  • Digital Magazine

© 2025 - CXO Insight Middle East. All Rights Reserved.