VenomLNK

First seen
2020-01-01 00:00:00
Malware type
loader
Last IoC activity
2026-07-18 18:47:31
Profile updated
2026-07-07 14:33:41

Targeted industries: financial-services professional-services technology-and-telecommunications

Context

VenomLNK is the initial phase of the more_eggs malware-as-a-service. It is a poisoned .lnk file that depends on User Execution and points to LOLBINs (often cmd.exe) with additional obfuscated scripting options. This typically initiates WMI abuse and TerraLoader, which can load additional functionality through various plugins.

Reports & references

  • esentire.com — Unmasking Venom Spider (report)
  • quointelligence.eu — Golden Chickens Evolution Of The Maas (report)
  • esentire.com — Hackers Spearphish Professionals On Linkedin With Fake Job Offers Infecting Them With Malware Warns Esentire (report)
  • esentire.com — Hackers Spearphish Corporate Hiring Managers With Poisoned Resumes Infecting Them With The More Eggs Malware (report)
  • medium.com — The Chicken Keeps Laying New Eggs Uncovering New Gc Maas Tools Used By Top Tier Threat Actors 531D80A6B4E9 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Venom Lnk (report)

External references