logo

Venom Spider Uses Server-Side Polymorphism to Weave a Web Around Victims

ID: 4c362b83-9fbf-526b-9ee8-3c45a0640650

STIX ID: report--4c362b83-9fbf-526b-9ee8-3c45a0640650

Feed Name: Arctic Wolf Blog

Threat Score
72/100

Date Published: 2025-05-02

Date Updated: 2026-04-27

...
...

Arctic Wolf Labs describes a Venom Spider (TA4557) spear-phishing campaign targeting HR and recruiters that uses polymorphic .lnk files and obfuscated JavaScript (More_eggs_Dropper and a JavaScript backdoor) to establish persistence, evade sandboxes, and execute a modular backdoor capable of credential and data theft; the report includes technical analysis, IOCs (hashes, domains, file paths), YARA rules, MITRE ATT&CK mapping, and remediation/detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.