Venom Loader is a malware loader associated with the Golden Chickens/Venom Spider malware-as-a-service ecosystem. Reporting from Zscaler ThreatLabz describes it as a newly identified loader observed in campaigns from September to October 2024 and delivered via VenomLNK social-engineering lures, including a cryptocurrency transaction-themed lure. In the observed infection chain, a VenomLNK stage wrote helper scripts to the Windows temporary directory, downloaded a ZIP archive from 170.75.168[.]151/%computername%/aaa, and executed ApplicationFrameHost.exe, which sideloaded a malicious dxgi.dll to launch Venom Loader.
Venom Loader is described as customized per victim: it used the victim computer name as a hardcoded XOR key to decode its payload. Zscaler assessed this victim-specific encoding as a notable evasion feature. The loader then decoded and launched a lightweight More_eggs JavaScript backdoor by reconstructing hello.js from text fragments via %APPDATA%\Adobe\merge.ps1. Persistence was established by adding merge.ps1 to HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run under the name GoogleUpdate. The resulting More_eggs lite backdoor continuously sent HTTP POST requests to /api/infos and executed XOR-decoded commands returned in JSON responses, providing remote code execution and persistence.
The malware is part of a broader Golden Chickens toolchain that also includes VenomLNK, TerraLoader, TerraStealer, TerraCrypt, and RevC2. Golden Chickens tooling has been linked in the provided content to financially motivated operations and use by groups such as FIN6 and Cobalt Group. High-confidence indicators mentioned in the content for activity involving Venom Loader include ApplicationFrameHost.exe and malicious dxgi.dll DLL sideloading, %APPDATA%\Adobe\merge.ps1, the Run key value GoogleUpdate, download infrastructure at hxxp://170.75.168[.]151/%computername%/aaa, and More_eggs lite C2 traffic to hxxp://65.38.121[.]211/api/infos. The reporting notes Venom Loader appeared to be an early version likely to gain additional features and anti-analysis capabilities over time.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Venom Loader is a new malware loader that is customized for each victim, using the victim’s computer name to encode the payload.
"F. Venom Loader Multi-stage payload deployment tool used to customize attack sequences."
"F. Venom Loader Multi-stage payload deployment tool used to customize attack sequences."
3 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader associated with the More_eggs MaaS ecosystem, used to deploy follow-on payloads.
"Related Families: VenomLNK, TerraLoader, TerraStealer, TerraTV, TerraCrypt, TerraRecon, TerraWiper, lite_more_eggs, RevC2, Venom Loader"
Venom Loader is a modular loader used by Golden Chickens to deliver additional payloads. It employs advanced evasion techniques such as victim-specific payload encoding, DLL side-loading, and persistence via autorun registry keys. It is used in spearphishing campaigns and supports multi-stage payload delivery.
Multi-stage loader used to tailor payload delivery based on victim architecture/security controls; often paired with fileless techniques to evade detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.