Venom Stealer is a malware-as-a-service infostealer and phishing kit reported by BlackFog that automates ClickFix-style social engineering attacks and extends beyond typical credential theft. It is sold by a developer using the handle "VenomStealer" via a subscription model with Telegram-based licensing, a vetted application process, and a 15% affiliate program. The platform embeds ClickFix lures directly into its operator panel and provides Windows and macOS templates including fake Cloudflare CAPTCHA, operating system update, SSL certificate error, and font installation pages. These lures instruct victims to open the Windows Run dialog or macOS Terminal, paste a command, and execute it, enabling user-initiated execution that can evade detections based on parent-child process relationships.
BlackFog reported that Venom Stealer delivers a native C++ payload compiled per operator from its web panel. Supported Windows delivery formats include EXE, PS1, HTA, and BAT, while macOS templates use bash and curl. After execution, the malware steals saved passwords, session cookies, browsing history, autofill data, and cryptocurrency wallet vaults from every profile in Chromium- and Firefox-based browsers. It also collects system fingerprinting data and browser extension inventories and exfiltrates the data immediately with little or no local staging.
The malware reportedly bypasses Chrome v10 and v20 password encryption using a silent privilege escalation, including use of the CMSTPLUA COM interface, to extract Chrome decryption keys without triggering a UAC dialog. BlackFog also reported that Venom Stealer persists after initial compromise and continuously monitors Chrome Login Data, polling every 30 seconds to capture newly saved credentials, which undermines password-reset-based response actions.
Venom Stealer also targets cryptocurrency users. Reported wallet targets include MetaMask, Phantom, Solflare, Trust Wallet, Atomic, Exodus, Electrum, Bitcoin Core, Monero, and Tonkeeper. Stolen wallet data is sent to a server-side GPU cracking engine used to crack and drain wallets across nine blockchain networks. A March 9, 2026 update added a File Password and Seed Finder that scans local filesystems for seed phrases and feeds them into the cracking pipeline. BlackFog reported multiple updates during March 2026, indicating active development.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The ClickFix pages instruct the victim to run commands in the Windows Run dialog or macOS Terminal, using EXE, PS1, HTA or BAT formats for Windows and bash and curl commands for macOS.
Once the payload runs, it immediately sweeps every Chromium and Firefox-based browser on the machine, extracting saved passwords, session cookies, browsing history, autofill data, and cryptocurrency wallet vaults from every profile.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commodity stealer/phishing kit that automates ClickFix social engineering attacks, installs via user-executed commands, and continuously exfiltrates data including saved passwords, session cookies, browsing history, autofill data, cryptocurrency wallet vaults, system fingerprints, and browser extension inventories. It also reportedly bypasses Chrome v10 and v20 password encryption using silent privilege escalation.
An infostealer MaaS platform that uses ClickFix social engineering for delivery, steals browser credentials, cookies, history, autofill data, and cryptocurrency wallet vaults, bypasses Chrome password encryption via CMSTPLUA COM-based privilege escalation, maintains persistence by continuously monitoring Chrome Login Data for newly saved credentials, and supports automated wallet cracking and draining.
Venom Stealer is a malware-as-a-service infostealer used in ClickFix social-engineering attacks. It is delivered via fake CAPTCHA, OS update, SSL certificate error, and font installation lures, and uses Windows and macOS command execution to infect victims. The malware targets Chromium and Firefox browsers to steal saved passwords, session cookies, browsing history, autofill data, and cryptocurrency wallet vaults. It reportedly bypasses Chrome v10 and v20 password encryption, rapidly exfiltrates data, persists on infected systems, monitors Chrome for newly saved credentials, and passes stolen wallet data to a wallet-cracking engine for theft of cryptocurrency funds.
An information-stealing malware-as-a-service platform that automates ClickFix-style social engineering attacks, delivers native payloads for Windows and macOS, steals credentials, cookies, browser data, and cryptocurrency wallet information, and maintains persistent monitoring for ongoing exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.