Venom Spider Uses Server-Side Polymorphism to Weave a Web Around Victims
Essential information
- Published
- 03/05/2025 03:04
- Modified
- 05/05/2025 18:09
- Tags
- 2025-05-03 backdoor evasion javascript lnk files more_eggs polymorphism spear-phishing
- Related entities
- 3 observables, 1 intrusion sets (apt), 8 techniques (mitre), 1 malware, 4 others
Description
Arctic Wolf Labs discovered a new campaign by Venom Spider targeting corporate HR departments with fake resumes containing the More_eggs backdoor. The financially motivated threat group uses spear-phishing emails and abuses legitimate job platforms to apply for real jobs. The backdoor can steal credentials, customer data, and intellectual property. Several upgrades were found, including server-side polymorphism and evasion techniques. The attack chain involves obfuscated JavaScript, LNK files, and a dropper that generates polymorphic code. Organizations are advised to train employees on phishing awareness, especially those in HR who regularly open attachments from unknown senders.