Venom Stealer Bypasses Chrome and “Auto-Cracks” Tonkeeper Wallets
ID: d461cdb2-2a54-54ff-949e-ea7085421357
STIX ID: report--d461cdb2-2a54-54ff-949e-ea7085421357
Feed Name: securityonline.info
Venom Stealer is a commercially offered Malware-as-a-Service platform that automates theft of browser credentials and cryptocurrency wallets (now including Tonkeeper support). The malware is distributed via tiered subscriptions and affiliates, delivered as custom C++ binaries with capabilities such as Chrome encryption bypass, silent UAC elevation, periodic exfiltration (session listener), and automated wallet cracking; it leverages social-engineering (“ClickFix”) and relies on PowerShell/Run dialog execution. BlackFog researchers observed active development and March 2026 updates, and recommend restricting PowerShell, disabling Run for standard users, user training, and outbound traffic monitoring to limit impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
