logo

Hackers Use Venom Stealer to Turn ClickFix Lures Into Full Data Exfiltration Pipelines

ID: a5f3caf2-36e1-5242-9cb5-2a4ede02d82d

STIX ID: report--a5f3caf2-36e1-5242-9cb5-2a4ede02d82d

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-04-03

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

Venom Stealer is a commercially distributed malware-as-a-service that uses ClickFix social-engineering templates to trick users into executing commands, then deploys a C++ infostealer that harvests browser credentials, cookies, autofill data and cryptocurrency wallets, maintains persistent session listeners to capture new credentials, and uses server-side GPU cracking to drain wallets; the platform is actively developed and sold via subscription with affiliate programs and operational updates. Suggested mitigations include restricting PowerShell and Run dialog use, outbound traffic monitoring, and user training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.