Skip to content

Venom

VENOM is a closed-access adversary-in-the-middle phishing platform discovered in 2026 that targets Microsoft 365 users, with a reported focus on senior executives and board-level personnel.

Profile source: Mallory opens in a new tab

Venom

Family profile

VENOM is a closed-access adversary-in-the-middle phishing platform discovered in 2026 that targets Microsoft 365 users, with a reported focus on senior executives and board-level personnel. It proxies legitimate authentication sessions to capture authenticated session material after victims complete normal sign-in and MFA workflows. The platform can establish persistence by silently registering an attacker-controlled authenticator on a compromised Microsoft Entra ID account during an active stolen session. This persistence can survive password resets and session revocation until the unauthorized authentication method is manually removed. VENOM is distinct from unrelated tools and criminal offerings that use the same name, including a Go-based reverse-proxy utility and cryptocurrency drainers.

Capabilities

  • Persistence
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 6, 2026
Last activity
Sep 7, 2026
Feed role
C2 / Distribution
Host form
2 IP / 0 hostnames

Leading locations

  • DE1
  • HK1

Leading providers

  • CTG Server Limited1
  • VPSLab Networks1

Infrastructure traits

  • Hosting 2

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
MuddyWater

Tooling: MERCURY’s tools of choice tend to be Venom proxy tool, Ligolo reverse tunneling, and home-grown PowerShell programs.

Blue Mockingbird

Blue Mockingbird has used frp, ssf, and Venom to establish SOCKS proxy connections.

MITRE ATT&CK

Venom in ATT&CK

23 distinct techniques

Reporting

Research mentioning Venom

Jul 23
Knowbe4

New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication

Active phishing campaigns are using the Jalisco and OmegaLord kits to compromise Microsoft 365 accounts with techniques designed to bypass or weaken multi-factor authentication. According to ReliaQuest, Jalisco abuses the OAuth 2.0 device authorization flow by generating fresh Microsoft device codes in real time and tricking victims into authorizing attacker-controlled devices, allowing attackers to obtain OAuth tokens without directly stealing passwords. OmegaLord uses a fake PDF reader login page to harvest credentials and victims’ phone numbers, which may help attackers intercept or manipulate MFA challenges. After gaining access, attackers have been observed moving quickly through SharePoint and other SaaS platforms to locate and exfiltrate sensitive data, sometimes within minutes, and may follow with extortion threats. ReliaQuest also reported that threat actors register multiple devices to compromised Microsoft Entra ID accounts to preserve access and refresh tokens even after password resets, reflecting a broader surge in phishing-as-a-service activity tied to platforms including EvilTokens, Kali365, Tycoon2FA, Venom, and Darcula. Defenders are being urged to reduce Entra ID device-registration limits, disable or restrict device code authentication through Conditional Access or Okta where not needed, and audit unnecessary app registrations.

Jul 18
Infosec Writeups

Medium

Jul 15
Techrepublic Com Security

Jalisco, OmegaLord Phishing Kits Target Microsoft 365 Accounts

Jul 14
ReliaQuest

Threat Spotlight: The Jalisco Toolkit and AI-Powered Phishing Surge

Jul 14
Bleeping Computer

New phishing kits target Microsoft 365 accounts, evade MFA

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.