VenomLNK
- First seen
- 2020-01-01 00:00:00
- Malware type
- loader
- Last IoC activity
- 2026-07-18 18:47:31
- Profile updated
- 2026-07-07 14:33:41
Targeted industries: financial-services professional-services technology-and-telecommunications
Context
VenomLNK is the initial phase of the more_eggs malware-as-a-service. It is a poisoned .lnk file that depends on User Execution and points to LOLBINs (often cmd.exe) with additional obfuscated scripting options. This typically initiates WMI abuse and TerraLoader, which can load additional functionality through various plugins.
Reports & references
- esentire.com — Unmasking Venom Spider (report)
- quointelligence.eu — Golden Chickens Evolution Of The Maas (report)
- esentire.com — Hackers Spearphish Professionals On Linkedin With Fake Job Offers Infecting Them With Malware Warns Esentire (report)
- esentire.com — Hackers Spearphish Corporate Hiring Managers With Poisoned Resumes Infecting Them With The More Eggs Malware (report)
- medium.com — The Chicken Keeps Laying New Eggs Uncovering New Gc Maas Tools Used By Top Tier Threat Actors 531D80A6B4E9 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Venom Lnk (report)