Many businesses in North and South America, as well as in Europe, have fallen victim to the infamous Valak Info Stealer.

According to Cisco Talos, Valak is distributed via malicious spam and usually along with secondary payloads, such as Gozi/Ursnif and IcedID.
Valak uses stolen email threads to spread, which often trick a user into opening the malicious attachments it contains.
The industries that have been hit the most by this Info Stealer lately are health, energy, transportation, insurance, etc
In one of the most recent attacks discovered, malicious actors sent a message in response to an old email they had sent to a bank months ago, which contained a malicious zip file.
Other similar attack attempts were observed at the same bank, including one in which an automated email sent from LinkedIn. A similar attack was also discovered against an insurance provider.

A common feature of the attacks was the ZIP file, which was even password-protected, which increased the likelihood of bypassing detection systems. In some cases, researchers found that some of these messages were forwarded to other recipients within the organization, including IT staff.
Talos further discovered that the attacks were carried out in multiple languages, including English, German, and Spanish. In most cases, their target was businesses and organizations, but there were also attacks on emails of individuals. However, as the security firm observed, the automation used by the hackers in their emails was not perfect, as some of the responses were invalid.
The campaigns were discovered as early as early 2020, but most of the attacks (95%) took place in May and June. While the attackers do not send large volumes of spam, their technique is what gives them high success rates.
