ThaiCERT    ETDA    MDES
Report
Search
Home > List all groups > List all tools > List all groups using tool VenomKit

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link Tool: VenomKit

NamesVenomKit
CategoryMalware
TypeLoader
Description(Proofpoint) We use this name to describe documents generated by a builder purchased from the same seller as Taurus builder. Depending on the variant it may exploit CVE-2017-0199, CVE-2017-8570, CVE-2017-8759, CVE-2017-11882, CVE-2018-0802, and/or CVE-2018-8174. Notably, VenomKit often also uses the same CMSTP bypass as Taurus Loader.
Information<https://www.proofpoint.com/us/threat-insight/post/fake-jobs-campaigns-delivering-moreeggs-backdoor-fake-job-offers>
<https://quointelligence.eu/2018/11/golden-chickens-uncovering-a-malware-as-a-service-maas-provider-and-two-new-threat-actors-using/>

Last change to this tool card: 09 July 2020

Download this tool card in JSON format

Previous: Veil
Next: VenomLNK

All groups using tool VenomKit

ChangedNameCountryObserved

APT groups

 Cobalt GroupRussia2016-Oct 2019X
 Venom Spider, Golden ChickensRussia2017-Feb 2019 

2 groups listed (2 APT, 0 other, 0 unknown)

Thailand Computer Emergency Response Team (ThaiCERT)
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1234
E-mail report@thaicert.or.th
PGP Download PGP key