Hackers Weaponize Venom Stealer via ClickFix Lures for Massive Data Exfiltration
ID: 08b8c0a3-564e-5ca8-b77a-0972df656869
STIX ID: report--08b8c0a3-564e-5ca8-b77a-0972df656869
Feed Name: GBHackers
Venom Stealer is a commercially operated malware-as-a-service that uses ClickFix social-engineering lures to get victims to run payloads (EXE, PowerShell, HTA, BAT on Windows and bash on macOS). It persistently monitors browser databases to exfiltrate credentials, session cookies, autofill data, and cryptocurrency wallet information, employs a silent CMSTPLUA UAC bypass to retrieve decryption keys, and forwards wallet material to a GPU-powered cracking pipeline and automated fund-transfer engine; mitigations include restricting PowerShell and Run dialog use and monitoring/blocking outbound connections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
