logo

Venom Spider Uses Server-Side Polymorphism to Weave a Web Around Victims

ID: eafd7ce9-e6ff-5a22-bd7b-3b1c761ffc7c

STIX ID: report--eafd7ce9-e6ff-5a22-bd7b-3b1c761ffc7c

Feed Name: Arctic Wolf

Threat Score
75/100

Date Published: 2025-05-02

Date Updated: 2026-07-26

Author: Arctic Wolf Labs

...
...

Arctic Wolf Labs reports that the financially motivated threat group Venom Spider (TA4557) is conducting a spear-phishing campaign against HR and recruitment staff by submitting malicious “resumes” that deliver a polymorphic JavaScript-based loader (More_eggs_Dropper) which ultimately deploys the More_eggs backdoor. The report includes a technical breakdown of the infection chain (LNK -> bat -> ie4uinit.inf -> obfuscated JS -> DLL dropper), C2 indicators, file and network IOCs, YARA rules, MITRE ATT&CK mappings, and recommended mitigations such as user training, EDR, and blocking identified infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.