VENOM is a closed-access adversary-in-the-middle phishing platform discovered in 2026 that targets Microsoft 365 users, with a reported focus on senior executives and board-level personnel. It proxies legitimate authentication sessions to capture authenticated session material after victims complete normal sign-in and MFA workflows. The platform can establish persistence by silently registering an attacker-controlled authenticator on a compromised Microsoft Entra ID account during an active stolen session. This persistence can survive password resets and session revocation until the unauthorized authentication method is manually removed. VENOM is distinct from unrelated tools and criminal offerings that use the same name, including a Go-based reverse-proxy utility and cryptocurrency drainers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Tooling: MERCURY’s tools of choice tend to be Venom proxy tool, Ligolo reverse tunneling, and home-grown PowerShell programs.
Blue Mockingbird has used frp, ssf, and Venom to establish SOCKS proxy connections.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
« [Le] device code phishing [est] une technique d’usurpation de compte exploitant le flux OAuth 2.0 Device Authorization Grant. »
« L’attaquant génère un code de périphérique [...] le transmet à la victime via phishing. »
The attacks begin with an email lure... The email contains a QR code constructed in HTML using Unicode characters rather than an image file... When the victim scans the QR code... they are met with a page that performs several checks to ensure they are the intended target and not a security scanner.
For persistence, the threat actor registers their reverse proxies as scheduled tasks, causing the reverse proxy to execute approximately every 20 minutes to communicate with the attacker’s C2 servers.
« [Le] device code phishing [est] une technique d’usurpation de compte exploitant le flux OAuth 2.0 Device Authorization Grant. »
The attacker then registers a new MFA device on the victim’s account for persistent access... The researchers noted that MFA devices registered through this campaign will appear in Entra ID logs as “SoftwareTokenActivated” events with the display name “NO_DEVICE.”
For persistence, the threat actor registers their reverse proxies as scheduled tasks, causing the reverse proxy to execute approximately every 20 minutes to communicate with the attacker’s C2 servers.
« [Le] device code phishing [est] une technique d’usurpation de compte exploitant le flux OAuth 2.0 Device Authorization Grant. »
The page performs several checks to ensure they are the intended target and not a security scanner... a user-agent screening is performed to detect headless browsers, automation frameworks and other signs of security tools... followed by a human-interaction gate... The last check is a proof-of-work challenge.
The attacker then registers a new MFA device on the victim’s account for persistent access... The researchers noted that MFA devices registered through this campaign will appear in Entra ID logs as “SoftwareTokenActivated” events with the display name “NO_DEVICE.”
« [L’attaquant] récupère des tokens d’accès et de rafraîchissement une fois que la victime entre le code sur la page légitime du fournisseur. »
The VENOM platform panel gives licensed users the ability to manage their phishing and credential harvesting campaigns, test and keep track of their live session tokens, and preserve raw OAuth server responses, potentially enabling the re-derivation of expired tokens.
The attacker then registers a new MFA device on the victim’s account for persistent access... The researchers noted that MFA devices registered through this campaign will appear in Entra ID logs as “SoftwareTokenActivated” events with the display name “NO_DEVICE.”
The page performs several checks to ensure they are the intended target and not a security scanner... a user-agent screening is performed to detect headless browsers, automation frameworks and other signs of security tools... followed by a human-interaction gate... The last check is a proof-of-work challenge.
Venom是一款为渗透测试人员设计的使用Go开发的多级代理工具。Venom可将多个节点进行连接,然后以节点为跳板,构建多级代理。渗透测试人员可以使用Venom轻松地将网络流量代理到多层内网
多级socks5代理 ... socks [lport] Start a socks5 server. ... 执行成功socks命令之后,会在admin节点本地开启一个端口...使用7777即可进行socks5代理 | 多级端口转发 ... lforward [lhost] [sport] [dport] Forward a local sport to a remote dport. rforward [rhost] [sport] [dport] Forward a remote sport to a local dport.
Several entries mention use of proxy and tunneling tools including PLINK, Venom proxy, GOST reverse proxy, Ligolo, Cloudflared, rsocx reverse proxy, Iox proxy tool, NPS tunneling tool, and AirVPN.
We already saw the usage of a HTTP tunnel tool to create a network tunnel between the infected system and a C2 server... several remote access tools such as Gh0stRAT and Venom multi-hop proxy were deployed
upload [local_file] [remote_file] Upload files to the target node. download [remote_file] [local_file] Download files from the target node.
Finally, several remote access tools such as Gh0stRAT and Venom multi-hop proxy were deployed on the machine, as well as a remote shell written purely in PowerShell.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Kit fermé de device-code phishing présentant des capacités similaires à EvilTokens.
A phishing kit mentioned as part of the broader ecosystem of kits used in recent phishing incidents.
A named crypto drainer active in 2024, associated with phishing campaigns that trick users into authorizing malicious transfers.
A closed-access adversary-in-the-middle phishing platform targeting executives. It steals active sessions by proxying real Microsoft logins and can use the stolen session to silently register an attacker-controlled authenticator on the victim’s Microsoft 365 account for persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.