VenomLNK is a malicious Windows shortcut used as an initial-access component in the Golden Chickens malware-as-a-service ecosystem, also tracked as Venom Spider. It is designed to trigger user execution and launch follow-on payloads such as TerraLoader, more_eggs, RevC2, and Venom Loader. The malware is commonly associated with targeted social-engineering operations rather than broad commodity spam, and has been linked to campaigns conducted by or in support of financially motivated actors including FIN6, Cobalt Group, Evilnum, and other customers of the Golden Chickens service.
VenomLNK is typically delivered through spearphishing lures, especially recruitment- and resume-themed messages, fake job offers, and similar business pretexts aimed at corporate employees and hiring managers. It has also been observed in ClickFix-adjacent delivery chains and in lure packages such as archives containing decoy documents. Once opened, the shortcut executes hidden scripts or trusted Windows utilities to stage the next payload while presenting a benign decoy to the victim. Reported execution chains include abuse of Windows Management Instrumentation and other living-off-the-land binaries to invoke loaders and evade detection.
Its primary role is to provide initial access and defense evasion for later Golden Chickens modules. In observed intrusions, VenomLNK has launched TerraLoader, which in turn can deploy modular capabilities including credential theft, reconnaissance, lateral movement support, remote shell access, and ransomware-enabling components. VenomLNK has therefore served as a recurring entry vector into financially motivated intrusions targeting sectors such as finance, e-commerce, legal services, staffing, aerospace and defense, healthcare technology, and other enterprise environments. It is best characterized as a malicious shortcut-based delivery mechanism within a broader modular intrusion toolkit rather than as a standalone payload with extensive post-compromise functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Upon downloading and executing the alleged job file, the TRU team saw that the victim unwittingly executed VenomLNK, an initial stage of more_eggs.
Additionally, Insikt Group tracks TAG-127 as a threat group that uses the TAG-195 MaaS, with ClickFix or VenomLNK as delivery methods.
Venom Spider, also known as GOLDEN CHICKENS, is a threat actor known for offering Malware-as-a-Service (MaaS) tools like VenomLNK, TerraLoader, TerraStealer, and TerraCryptor.
Venom Spider, also known as GOLDEN CHICKENS, is a threat actor known for offering Malware-as-a-Service (MaaS) tools like VenomLNK, TerraLoader, TerraStealer, and TerraCryptor.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
TRU has uncovered a more_eggs phishing campaign where hackers are posing as job applicants and luring Corporate Hiring Managers into downloading what they believe are resumes from job applicants.
The hackers sent the job seekers .zip files disguised as job offers. When the targets opened the zip file, it led to the installation of more_eggs.
The operators then send a link leading to a mock resume PDF through the organization‘s recruitment platform (e.g. Indeed, LinkedIn, or the organization‘s own career web page). The PDF purports to be broken, offering an embedded link to the malicious VenomLNK file on the branding website.
By abusing Windows Management Instrumentation, VenomLNK enables the malware’s plugin loader, TerraLoader
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named malware/tool referenced as a delivery method used alongside TAG-195 MaaS operations by TAG-127.
LNK-based initial access mechanism used to deliver follow-on malware in the More_eggs ecosystem.
"Related Families: VenomLNK, TerraLoader, TerraStealer, TerraTV, TerraCrypt, TerraRecon, TerraWiper, lite_more_eggs, RevC2, Venom Loader"
Malicious Windows shortcut (LNK) used for initial access via spear-phishing; triggers execution of hidden PowerShell and/or deployment of secondary payloads, often delivered inside ZIP/ISO attachments to evade filtering.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.