Last seven days
- First activity
- Sep 6, 2026
- Last activity
- Sep 7, 2026
- Feed role
- C2 / Distribution
- Host form
- 2 IP / 0 hostnames
VENOM is a closed-access adversary-in-the-middle phishing platform discovered in 2026 that targets Microsoft 365 users, with a reported focus on senior executives and board-level personnel.
Profile source: Mallory opens in a new tabVenom
VENOM is a closed-access adversary-in-the-middle phishing platform discovered in 2026 that targets Microsoft 365 users, with a reported focus on senior executives and board-level personnel. It proxies legitimate authentication sessions to capture authenticated session material after victims complete normal sign-in and MFA workflows. The platform can establish persistence by silently registering an attacker-controlled authenticator on a compromised Microsoft Entra ID account during an active stolen session. This persistence can survive password resets and session revocation until the unauthorized authentication method is manually removed. VENOM is distinct from unrelated tools and criminal offerings that use the same name, including a Go-based reverse-proxy utility and cryptocurrency drainers.
C2 tracking
Derp observations, rolling seven-day window
Samples
08295c1247b7ce6dc020bfba5ba75540e3b5c98665ba99f2f73b37016811f47c 1159cff4969f8e7f7454e6fe8a97aa0a73b455460e2abf0c87f1343972d58a9a 1fbdcb873815e0bbb99531777ab9c5cb853078708ead0b0436191a66f59bb02b 9b1d38cd728ec1a478db668e86f7445ab5f0335b388feefc15502931cdcad704 f959a8494f2a1c4e11f346ae8e3099593f156be2a5c8010d1747e4466a11316a 10144705b7acb9987eb6230ec7b472358c3d777af913b39519ef4ea7a4eda0b2 2f1a106977c45b7bd98c0a00688fda7ce5281ad0ad8bf9ad86609cb6993f73f9 49de2df0bd77633db88406562eacd65b4cea666cb8407ea87713870c51d6a95d 7f7c84705866efd8f4185f424f9fe18016bd4173fd07df0912af90ddd9ca5836 cc254bfbea8a3bb6be96679955c6863d51457c80a3a27fe8353a912a87db696b Reported operators
Tooling: MERCURY’s tools of choice tend to be Venom proxy tool, Ligolo reverse tunneling, and home-grown PowerShell programs.
Blue Mockingbird has used frp, ssf, and Venom to establish SOCKS proxy connections.
MITRE ATT&CK
Reporting
Active phishing campaigns are using the Jalisco and OmegaLord kits to compromise Microsoft 365 accounts with techniques designed to bypass or weaken multi-factor authentication. According to ReliaQuest, Jalisco abuses the OAuth 2.0 device authorization flow by generating fresh Microsoft device codes in real time and tricking victims into authorizing attacker-controlled devices, allowing attackers to obtain OAuth tokens without directly stealing passwords. OmegaLord uses a fake PDF reader login page to harvest credentials and victims’ phone numbers, which may help attackers intercept or manipulate MFA challenges. After gaining access, attackers have been observed moving quickly through SharePoint and other SaaS platforms to locate and exfiltrate sensitive data, sometimes within minutes, and may follow with extortion threats. ReliaQuest also reported that threat actors register multiple devices to compromised Microsoft Entra ID accounts to preserve access and refresh tokens even after password resets, reflecting a broader surge in phishing-as-a-service activity tied to platforms including EvilTokens, Kali365, Tycoon2FA, Venom, and Darcula. Defenders are being urged to reduce Entra ID device-registration limits, disable or restrict device code authentication through Conditional Access or Okta where not needed, and audit unnecessary app registrations.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.