Last seven days
- First activity
- Aug 15, 2026
- Last activity
- Aug 15, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
Venom is a name used for multiple distinct malicious or dual-use toolsets, but the strongest high-confidence usage in this context refers to a Go-based proxy and tunneling utility used by intrusion operators to establish reverse proxy or SOCKS-style connectivity inside compromised environments.
Profile source: Mallory opens in a new tabVenom
Venom is a name used for multiple distinct malicious or dual-use toolsets, but the strongest high-confidence usage in this context refers to a Go-based proxy and tunneling utility used by intrusion operators to establish reverse proxy or SOCKS-style connectivity inside compromised environments. It has been observed as customized post-compromise tooling in espionage and financially motivated intrusions, including activity associated with Lotus Blossom, Blue Mockingbird, and MERCURY/Mango Sandstorm, where operators used it to relay traffic, maintain command-and-control access, and support internal pivoting. Reported customizations include hardcoded destination infrastructure and adaptation for stealthier operational use. The tool is associated with Windows intrusions and is typically deployed after initial compromise as part of lateral movement, persistence support, or broader post-exploitation tradecraft rather than as a standalone initial-access payload.
The name Venom has also been used in unrelated criminal ecosystems, including phishing-as-a-service and cryptocurrency drainer operations, but those references do not describe the same malware family or provide enough overlap to unify them as a single malware entry. Security practitioners should therefore disambiguate Venom by context; in intrusion reporting it most commonly denotes the proxy tool used for covert tunneling and operator access.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
Tooling: MERCURY’s tools of choice tend to be Venom proxy tool, Ligolo reverse tunneling, and home-grown PowerShell programs.
Blue Mockingbird has used frp, ssf, and Venom to establish SOCKS proxy connections.
MITRE ATT&CK
Reporting
Active phishing campaigns are using the Jalisco and OmegaLord kits to compromise Microsoft 365 accounts with techniques designed to bypass or weaken multi-factor authentication. According to ReliaQuest, Jalisco abuses the OAuth 2.0 device authorization flow by generating fresh Microsoft device codes in real time and tricking victims into authorizing attacker-controlled devices, allowing attackers to obtain OAuth tokens without directly stealing passwords. OmegaLord uses a fake PDF reader login page to harvest credentials and victims’ phone numbers, which may help attackers intercept or manipulate MFA challenges. After gaining access, attackers have been observed moving quickly through SharePoint and other SaaS platforms to locate and exfiltrate sensitive data, sometimes within minutes, and may follow with extortion threats. ReliaQuest also reported that threat actors register multiple devices to compromised Microsoft Entra ID accounts to preserve access and refresh tokens even after password resets, reflecting a broader surge in phishing-as-a-service activity tied to platforms including EvilTokens, Kali365, Tycoon2FA, Venom, and Darcula. Defenders are being urged to reduce Entra ID device-registration limits, disable or restrict device code authentication through Conditional Access or Okta where not needed, and audit unnecessary app registrations.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.