VENOM is a closed-access adversary-in-the-middle phishing platform focused on compromising Microsoft 365 accounts belonging to senior business leaders. It was identified in 2026 and is characterized by selective targeting of executives, with a substantial share of observed victims holding C-level or board positions. VENOM captures valid authenticated sessions through AiTM phishing that proxies the legitimate Microsoft sign-in flow, allowing it to bypass common MFA mechanisms such as SMS, one-time passcodes, and push approvals. After obtaining access, the platform has been associated with persistence through silent registration of an attacker-controlled authenticator on the victim’s Microsoft Entra ID account, enabling continued access even after password resets or session revocation unless the rogue authentication method is manually removed. VENOM appears to be operated as a restricted platform rather than an openly marketed phishing service, indicating controlled access and a curated operator or customer base. Its tradecraft centers on initial access, session hijacking, and persistence against high-value enterprise identities, especially executive accounts in Microsoft 365 environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Closed-access AiTM phishing platform targeting executives, using QR-code delivery, anti-scanner protections, session theft, and persistence through silent MFA device registration.
Closed-access phishing platform targeting executives using adversary-in-the-middle phishing to steal sessions and then silently register attacker-controlled MFA devices for persistence.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.