logo

Venom Spider Spins Web of New Malware for MaaS Platform

ID: 1f85166c-be78-55b4-8b39-cf7662f673c3

STIX ID: report--1f85166c-be78-55b4-8b39-cf7662f673c3

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2024-12-03

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Zscaler ThreatLabz observed Venom Spider (MaaS) campaigns from August–October delivering two new malware families: RevC2, a WebSocket-based backdoor that steals browser credentials/cookies, proxies traffic (SOCKS5), captures screenshots and enables RCE; and Venom Loader, which customizes and XOR-encodes payloads per victim using the machine name to deploy a JavaScript RCE backdoor (“More_eggs lite”). Researchers published IoCs, a Python WebSocket emulation script, and noted the platform’s likely continued enhancement and reuse by criminal groups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.