VenomLNK is a malicious Windows shortcut used as an initial-access component in the Golden Chickens malware-as-a-service ecosystem, also associated with the threat actor tracked as Venom Spider. It is used to initiate multi-stage intrusions by executing hidden scripts and launching follow-on payloads, commonly including other Golden Chickens tooling such as TerraLoader, RevC2, and Venom Loader. VenomLNK has been repeatedly linked to financially motivated intrusion activity and has been used by downstream operators and customers of the Golden Chickens service model.
The malware is primarily associated with social-engineering delivery, especially spearphishing campaigns in which shortcut files are used to trigger execution chains on Windows systems. Reported activity shows VenomLNK functioning as a delivery mechanism and initial infection vector rather than as a full-featured payload in its own right. Observed execution chains include use of obfuscated batch logic, hidden PowerShell, and trusted Windows utilities to retrieve or launch secondary malware. VenomLNK has also been associated with campaigns using lures themed around business or cryptocurrency-related content.
Within the broader Golden Chickens toolchain, VenomLNK serves as a staple first-stage access method designed to hand off execution to more capable implants. Those downstream payloads have supported credential theft, browser data theft, remote command execution, persistence, and other post-compromise actions, making VenomLNK an important enabler of financially motivated operations. Its role in repeated campaigns and its close integration with other Golden Chickens families make it a core component of that MaaS ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Additionally, Insikt Group tracks TAG-127 as a threat group that uses the TAG-195 MaaS, with ClickFix or VenomLNK as delivery methods.
Venom Spider, also known as GOLDEN CHICKENS, is a threat actor known for offering Malware-as-a-Service (MaaS) tools like VenomLNK, TerraLoader, TerraStealer, and TerraCryptor.
Venom Spider, also known as GOLDEN CHICKENS, is a threat actor known for offering Malware-as-a-Service (MaaS) tools like VenomLNK, TerraLoader, TerraStealer, and TerraCryptor.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named malware/tool referenced as a delivery method used alongside TAG-195 MaaS operations by TAG-127.
LNK-based initial access mechanism used to deliver follow-on malware in the More_eggs ecosystem.
"Related Families: VenomLNK, TerraLoader, TerraStealer, TerraTV, TerraCrypt, TerraRecon, TerraWiper, lite_more_eggs, RevC2, Venom Loader"
Malicious Windows shortcut (LNK) used for initial access via spear-phishing; triggers execution of hidden PowerShell and/or deployment of secondary payloads, often delivered inside ZIP/ISO attachments to evade filtering.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.