Venom is a name used for multiple distinct malicious or dual-use toolsets, but the strongest high-confidence usage in this context refers to a Go-based proxy and tunneling utility used by intrusion operators to establish reverse proxy or SOCKS-style connectivity inside compromised environments. It has been observed as customized post-compromise tooling in espionage and financially motivated intrusions, including activity associated with Lotus Blossom, Blue Mockingbird, and MERCURY/Mango Sandstorm, where operators used it to relay traffic, maintain command-and-control access, and support internal pivoting. Reported customizations include hardcoded destination infrastructure and adaptation for stealthier operational use. The tool is associated with Windows intrusions and is typically deployed after initial compromise as part of lateral movement, persistence support, or broader post-exploitation tradecraft rather than as a standalone initial-access payload.
The name Venom has also been used in unrelated criminal ecosystems, including phishing-as-a-service and cryptocurrency drainer operations, but those references do not describe the same malware family or provide enough overlap to unify them as a single malware entry. Security practitioners should therefore disambiguate Venom by context; in intrusion reporting it most commonly denotes the proxy tool used for covert tunneling and operator access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Tooling: MERCURY’s tools of choice tend to be Venom proxy tool, Ligolo reverse tunneling, and home-grown PowerShell programs.
Blue Mockingbird has used frp, ssf, and Venom to establish SOCKS proxy connections.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
...the surge of account takeover accounts facilitated by OAuth 2.0 Device Authorization Grant flow exploitation...
Phishing has surged in 2026 as AI-powered phishing-as-a-service (PhaaS) kits enable attackers to bypass MFA and harvest OAuth tokens at scale.
The attacks begin with an email lure... The email contains a QR code constructed in HTML using Unicode characters rather than an image file... When the victim scans the QR code... they are met with a page that performs several checks to ensure they are the intended target and not a security scanner.
For persistence, the threat actor registers their reverse proxies as scheduled tasks, causing the reverse proxy to execute approximately every 20 minutes to communicate with the attacker’s C2 servers.
...the surge of account takeover accounts facilitated by OAuth 2.0 Device Authorization Grant flow exploitation...
The attacker then registers a new MFA device on the victim’s account for persistent access... The researchers noted that MFA devices registered through this campaign will appear in Entra ID logs as “SoftwareTokenActivated” events with the display name “NO_DEVICE.”
For persistence, the threat actor registers their reverse proxies as scheduled tasks, causing the reverse proxy to execute approximately every 20 minutes to communicate with the attacker’s C2 servers.
...the surge of account takeover accounts facilitated by OAuth 2.0 Device Authorization Grant flow exploitation...
The page performs several checks to ensure they are the intended target and not a security scanner... a user-agent screening is performed to detect headless browsers, automation frameworks and other signs of security tools... followed by a human-interaction gate... The last check is a proof-of-work challenge.
The attacker then registers a new MFA device on the victim’s account for persistent access... The researchers noted that MFA devices registered through this campaign will appear in Entra ID logs as “SoftwareTokenActivated” events with the display name “NO_DEVICE.”
The device code version of the phishing attack presents the target with a verification prompt to access a Docusign document. This page abuses the device code authentication flow... The victim is directed to a legitimate Microsoft page where they submit the code and log in, unknowingly giving the attacker’s device access to their account.
The VENOM platform panel gives licensed users the ability to manage their phishing and credential harvesting campaigns, test and keep track of their live session tokens, and preserve raw OAuth server responses, potentially enabling the re-derivation of expired tokens.
The attacker then registers a new MFA device on the victim’s account for persistent access... The researchers noted that MFA devices registered through this campaign will appear in Entra ID logs as “SoftwareTokenActivated” events with the display name “NO_DEVICE.”
The page performs several checks to ensure they are the intended target and not a security scanner... a user-agent screening is performed to detect headless browsers, automation frameworks and other signs of security tools... followed by a human-interaction gate... The last check is a proof-of-work challenge.
Venom是一款为渗透测试人员设计的使用Go开发的多级代理工具。Venom可将多个节点进行连接,然后以节点为跳板,构建多级代理。渗透测试人员可以使用Venom轻松地将网络流量代理到多层内网
多级socks5代理 ... socks [lport] Start a socks5 server. ... 执行成功socks命令之后,会在admin节点本地开启一个端口...使用7777即可进行socks5代理 | 多级端口转发 ... lforward [lhost] [sport] [dport] Forward a local sport to a remote dport. rforward [rhost] [sport] [dport] Forward a remote sport to a local dport.
Several entries mention use of proxy and tunneling tools including PLINK, Venom proxy, GOST reverse proxy, Ligolo, Cloudflared, rsocx reverse proxy, Iox proxy tool, NPS tunneling tool, and AirVPN.
We already saw the usage of a HTTP tunnel tool to create a network tunnel between the infected system and a C2 server... several remote access tools such as Gh0stRAT and Venom multi-hop proxy were deployed
upload [local_file] [remote_file] Upload files to the target node. download [remote_file] [local_file] Download files from the target node.
Finally, several remote access tools such as Gh0stRAT and Venom multi-hop proxy were deployed on the machine, as well as a remote shell written purely in PowerShell.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A phishing kit mentioned as part of the broader ecosystem of kits used in recent phishing incidents.
A named crypto drainer active in 2024, associated with phishing campaigns that trick users into authorizing malicious transfers.
A closed-access adversary-in-the-middle phishing platform targeting executives. It steals active sessions by proxying real Microsoft logins and can use the stolen session to silently register an attacker-controlled authenticator on the victim’s Microsoft 365 account for persistence.
Referenced as an existing stealer used for comparison against Noobsaibot; no further functional detail is provided in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.