Venom Spider Spins Web of New Malware for MaaS Platform
ID: 1f85166c-be78-55b4-8b39-cf7662f673c3
STIX ID: report--1f85166c-be78-55b4-8b39-cf7662f673c3
Feed Name: Dark Reading
Date Published: 2024-12-03
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Zscaler ThreatLabz observed Venom Spider (MaaS) campaigns from August–October delivering two new malware families: RevC2, a WebSocket-based backdoor that steals browser credentials/cookies, proxies traffic (SOCKS5), captures screenshots and enables RCE; and Venom Loader, which customizes and XOR-encodes payloads per victim using the machine name to deploy a JavaScript RCE backdoor (“More_eggs lite”). Researchers published IoCs, a Python WebSocket emulation script, and noted the platform’s likely continued enhancement and reuse by criminal groups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
