#venomrat — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #venomrat, aggregated by home.social.
-
#OperationEndgame3: 1025 Server von Netz genommen | Security https://www.heise.de/news/Operation-Endgame-3-1025-Server-von-Netz-genommen-11077049.html #OperationEndgame #Malware #Infostealer #Botnet #Elysium #VenomRAT #Rhadamanthys
-
#OperationEndgame3: 1025 Server von Netz genommen | Security https://www.heise.de/news/Operation-Endgame-3-1025-Server-von-Netz-genommen-11077049.html #OperationEndgame #Malware #Infostealer #Botnet #Elysium #VenomRAT #Rhadamanthys
-
Lees tip -> Operatie Endgame schakelt grote cybernetwerken uit | In Operatie Endgame zijn grote cybernetwerken uitgeschakeld, met aanhoudingen, neergehaalde servers en verstoring van infostealers, botnets en RAT’s door internationale samenwerking. | #botnet #cybercrime #Europol #hacking #infostealers #internationalesamenwerking #OperatieEndgame #politie #ransomware #Rhadamanthys #VenomRAT |
https://hbpmedia.nl/operatie-endgame-cybernetwerken-uitgeschakeld/
-
Operation Endgame Hits Rhadamanthys, VenomRAT, Elysium Malware, seize 1025 servers https://hackread.com/operation-endgame-rhadamanthys-venomrat-elysium-malware/ #OperationEndgame #Rhadamanthys #Infostealer #CyberCrime #security #VenomRAT #Malware #Police
-
Operation Endgame Hits Rhadamanthys, VenomRAT, Elysium Malware, seize 1025 servers https://hackread.com/operation-endgame-rhadamanthys-venomrat-elysium-malware/ #OperationEndgame #Rhadamanthys #Infostealer #CyberCrime #security #VenomRAT #Malware #Police
-
Operation Endgame Takedown Hits Rhadamanthys and VenomRAT https://dailydarkweb.net/operation-endgame-takedown-hits-rhadamanthys-and-venomrat/ #DarkWebNews&Services #OperationEndgame #Rhadamanthys #infostealer #cybercrime #Eurojust #takedown #VenomRAT #Elysium #Europol #malware #Season3
-
Operation Endgame Takedown Hits Rhadamanthys and VenomRAT https://dailydarkweb.net/operation-endgame-takedown-hits-rhadamanthys-and-venomrat/ #DarkWebNews&Services #OperationEndgame #Rhadamanthys #infostealer #cybercrime #Eurojust #takedown #VenomRAT #Elysium #Europol #malware #Season3
-
1,000+ Servers Hit in Law Enforcement Takedown of Rhadamanthys, VenomRAT, Elysium https://www.securityweek.com/1000-servers-hit-in-law-enforcement-takedown-of-rhadamanthys-venomrat-elysium/ #Tracking&LawEnforcement #lawenforcement #Rhadamanthys #infostealer #takedown #VenomRAT #Elysium #Europol #botnet
-
1,000+ Servers Hit in Law Enforcement Takedown of Rhadamanthys, VenomRAT, Elysium https://www.securityweek.com/1000-servers-hit-in-law-enforcement-takedown-of-rhadamanthys-venomrat-elysium/ #Tracking&LawEnforcement #lawenforcement #Rhadamanthys #infostealer #takedown #VenomRAT #Elysium #Europol #botnet
-
Operation Endgame’s latest phase targeted the infostealer #Rhadamanthys, Remote Access Trojan #VenomRAT, and the botnet #Elysium.
https://www.europol.europa.eu/media-press/newsroom/news/end-of-game-for-cybercrime-infrastructure-1025-servers-taken-down -
Operation Endgame’s latest phase targeted the infostealer #Rhadamanthys, Remote Access Trojan #VenomRAT, and the botnet #Elysium.
https://www.europol.europa.eu/media-press/newsroom/news/end-of-game-for-cybercrime-infrastructure-1025-servers-taken-down -
Operation Endgame Dismantles 1,025 Servers in a Strike Against Rhadamanthys, VenomRAT Operations https://thecyberexpress.com/operation-endgame-dismantle-rhadamanthys/ #ThreatIntelligenceNews #ThreatIntelligence #OperationEndgame #CyberEssentials #ThreatActors #Rhadamanthys #infostealer #CyberNews #VenomRAT
-
Operation Endgame Dismantles 1,025 Servers in a Strike Against Rhadamanthys, VenomRAT Operations https://thecyberexpress.com/operation-endgame-dismantle-rhadamanthys/ #ThreatIntelligenceNews #ThreatIntelligence #OperationEndgame #CyberEssentials #ThreatActors #Rhadamanthys #infostealer #CyberNews #VenomRAT
-
And it's out!
End of the game for cybercrime infrastructure: 1025 servers taken down
Between 10 and 13 November 2025, the latest phase of Operation Endgame was coordinated from Europol’s headquarters in The Hague. The actions targeted one of the biggest infostealer Rhadamanthys, the Remote Access Trojan VenomRAT, and the botnet Elysium, all of which played a key role in international cybercrime. Authorities took down these three large cybercrime enablers. The main suspect for VenomRAT was arrested in Greece on 3 November 2025.
#OperationEndgame #rhadamanthys #infostealer #VenomRAT #Elysium
-
And it's out!
End of the game for cybercrime infrastructure: 1025 servers taken down
Between 10 and 13 November 2025, the latest phase of Operation Endgame was coordinated from Europol’s headquarters in The Hague. The actions targeted one of the biggest infostealer Rhadamanthys, the Remote Access Trojan VenomRAT, and the botnet Elysium, all of which played a key role in international cybercrime. Authorities took down these three large cybercrime enablers. The main suspect for VenomRAT was arrested in Greece on 3 November 2025.
#OperationEndgame #rhadamanthys #infostealer #VenomRAT #Elysium
-
Threat Actor Infests Hotels With New RAT https://www.securityweek.com/threat-actor-infests-hotels-with-new-rat/ #Malware&Threats #RevengeHotels #VenomRAT #hotel #RAT
-
Threat Actor Infests Hotels With New RAT https://www.securityweek.com/threat-actor-infests-hotels-with-new-rat/ #Malware&Threats #RevengeHotels #VenomRAT #hotel #RAT
-
Threat Actor Infests Hotels With New RAT https://www.securityweek.com/threat-actor-infests-hotels-with-new-rat/ #Malware&Threats #RevengeHotels #VenomRAT #hotel #RAT
-
Threat Actor Infests Hotels With New RAT https://www.securityweek.com/threat-actor-infests-hotels-with-new-rat/ #Malware&Threats #RevengeHotels #VenomRAT #hotel #RAT
-
RevengeHotels: a new wave of attacks leveraging LLMs and VenomRAT
#RevengeHotels #VenomRAT
https://securelist.com/revengehotels-attacks-with-ai-and-venomrat-across-latin-america/117493/ -
RevengeHotels: a new wave of attacks leveraging LLMs and VenomRAT
#RevengeHotels #VenomRAT
https://securelist.com/revengehotels-attacks-with-ai-and-venomrat-across-latin-america/117493/ -
🎣 Phishing Campaign
====================🎯 Threat Intelligence
Executive summary: RevengeHotels, tracked as TA558, has launched a new campaign focused on targets in Latin America. The operation combines social‑engineering lures generated or refined with LLMs and a multi‑stage payload delivery that includes VenomRAT as a secondary implant.
Technical details: The research attributed to Kaspersky GReAT describes an initial infection vector using convincing lures (reports indicate use of large language models to craft messages and
attachments) followed by deployment of a malicious implant and a second loading step that delivers VenomRAT. Additional behaviours reported include USB spreading and anti‑kill mechanisms intended to maintain persistence and hinder remediation.Analysis & impact: The group’s historical goal of payment‑card harvesting aligns with observed tooling and TTPs; VenomRAT provides remote access and data‑collection capabilities that enable payment‑card skimming and exfiltration. Use of LLMs to tailor lures increases phishing efficacy and may broaden victim scope across industries in the region.
Detection: Monitor for anomalous post‑delivery processes and new persistence artifacts, uncommon USB autorun or device enumeration activity, and network connections associated with known VenomRAT command‑and‑control patterns. Endpoint telemetry showing staged downloads after opening social‑engineering attachments is a high‑value detection signal. No precise IoCs were included in the supplied excerpt.
Mitigation: Enforce multi‑layer controls: block known malicious file types at mail gateways, apply strict device control policies for removable media, enforce EDR detections for process injection and persistence modification, and treat unsolicited attachments with elevated suspicion, especially those leveraging sophisticated social engineering likely crafted by LLMs.
References & caveats: Findings are derived from a Kaspersky GReAT report; technical artifacts and IoCs were not fully available in the supplied text. Further validation against full indicators is recommended.
🔹 RevengeHotels #VenomRAT #TA558 #LLM
🔗 Source: https://securelist.com/revengehotels-attacks-with-ai-and-venomrat-across-latin-america/117493/
-
Unmasking AsyncRAT: Navigating the labyrinth of forks
#AsyncRAT #DCRat #VenomRAT #BoratRAT #NonEuclidRAT #JasonRAT #XieBroRAT
https://www.welivesecurity.com/en/eset-research/unmasking-asyncrat-navigating-labyrinth-forks/ -
Unmasking AsyncRAT: Navigating the labyrinth of forks
#AsyncRAT #DCRat #VenomRAT #BoratRAT #NonEuclidRAT #JasonRAT #XieBroRAT
https://www.welivesecurity.com/en/eset-research/unmasking-asyncrat-navigating-labyrinth-forks/ -
Hackers Hide VenomRAT Malware Inside Virtual Hard Disk Image File https://hackread.com/hackers-hide-venomrat-malware-virtual-hard-disk-files/ #Cybersecurity #PhishingScam #CyberAttack #Security #Phishing #security #VenomRAT #Malware #HVNC #Scam
-
Hackers Hide VenomRAT Malware Inside Virtual Hard Disk Image File https://hackread.com/hackers-hide-venomrat-malware-virtual-hard-disk-files/ #Cybersecurity #PhishingScam #CyberAttack #Security #Phishing #security #VenomRAT #Malware #HVNC #Scam
-
Hackers Hide VenomRAT Malware Inside Virtual Hard Disk Image File – Source:hackread.com https://ciso2ciso.com/hackers-hide-venomrat-malware-inside-virtual-hard-disk-image-file-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #PhishingScam #CyberAttack #Hackread #Phishing #security #VenomRAT #malware #HVNC #Scam
-
Hackers Hide VenomRAT Malware Inside Virtual Hard Disk Image File – Source:hackread.com https://ciso2ciso.com/hackers-hide-venomrat-malware-inside-virtual-hard-disk-image-file-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #PhishingScam #CyberAttack #Hackread #Phishing #security #VenomRAT #malware #HVNC #Scam
-
NEW🚨- Hackers are hiding the notorious #VenomRAT malware inside Virtual Hard Disk (VHD) image files.
Read: https://hackread.com/hackers-hide-venomrat-malware-virtual-hard-disk-files/
-
NEW🚨- Hackers are hiding the notorious #VenomRAT malware inside Virtual Hard Disk (VHD) image files.
Read: https://hackread.com/hackers-hide-venomrat-malware-virtual-hard-disk-files/
-
2025-02-25 (Tuesday): #VenomRAT from #malspam uses zip attachment containing a VHD file containing a VBS file. Calls Pastebin link for C2 server information. Details at https://github.com/malware-traffic/indicators/blob/main/2025-02-25-IOCs-for-Venom-RAT-activity.txt
-
2025-02-25 (Tuesday): #VenomRAT from #malspam uses zip attachment containing a VHD file containing a VBS file. Calls Pastebin link for C2 server information. Details at https://github.com/malware-traffic/indicators/blob/main/2025-02-25-IOCs-for-Venom-RAT-activity.txt
-
When the threat actor REALLY wants it to run... #venomrat c2:
176.65.142.172:4449
-
http://trackingshipmentt\.xyz:9394/
http://trackmyshipeng\.site:9094/https://app.any.run/tasks/086f767d-cb57-46d0-80f6-1d771148444e/
-
Анализ фишинга с Venom RAT
В начале апреля в организации Российской Федерации (и не только) пришли письма от неизвестного отправителя. В содержимом письма, кроме пожелания хорошего дня и просьбой ответить «скорее», находился RAR архив, а внутри архива *.bat файл. После проверки содержимого в песочнице были предоставлены некоторые артефакты, указывая, что в письме явно содержится что-то подозрительное, но определить наверняка, вредонос это или нет СЗИ не удалось. Зато были указаны некоторые составляющие bat файла: обфусцированные строки PowerShell. Этого было достаточно чтобы начать анализ содержимого, найти IoC’и, и посмотреть на наличие таковых в трафике от организации. К анализу.
-
Fortinet reports on a recent phishing campaign containing Scalable Vector Graphics (SVG) files. The malicious attachment downloads a ZIP file and begins the infection chain. ScrubCrypt, described as an "antivirus evasion tool", is used to load the final payload VenomRAT while maintaining a connection with the C2 server to install plugins like XWorm, NanoCore, RemcosRAT and a crypto wallet stealer. They provides detailed insights into how the threat actor distributes VenomRAT and other plugins. IOC listed. 🔗 https://www.fortinet.com/blog/threat-research/scrubcrypt-deploys-venomrat-with-arsenal-of-plugins
#ScrubCrypt #VenomRAT #RemcosRAT #XWorm #NanoCore #threatintel #IOC
-
Fortinet reports on a recent phishing campaign containing Scalable Vector Graphics (SVG) files. The malicious attachment downloads a ZIP file and begins the infection chain. ScrubCrypt, described as an "antivirus evasion tool", is used to load the final payload VenomRAT while maintaining a connection with the C2 server to install plugins like XWorm, NanoCore, RemcosRAT and a crypto wallet stealer. They provides detailed insights into how the threat actor distributes VenomRAT and other plugins. IOC listed. 🔗 https://www.fortinet.com/blog/threat-research/scrubcrypt-deploys-venomrat-with-arsenal-of-plugins
#ScrubCrypt #VenomRAT #RemcosRAT #XWorm #NanoCore #threatintel #IOC
-
Proof-of-Concept-#Exploit für #WinRAR-Lücke bringt #VenomRAT-#Malware mit | Security https://www.heise.de/news/Proof-of-Concept-Exploit-fuer-WinRAR-Luecke-bringt-VenomRAT-Malware-mit-9313479.html #ProofOfConcept #PoC
-
Unit42: Fake CVE-2023-40477 Proof of Concept Leads to VenomRAT https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/ #AdvancedURLFiltering #remotecodeexecution #RemoteAccessTrojan #socialengineering #CVE-2023-25157 #CVE-2023-40477 #ProofofConcept #Vulnerability #VenomRAT #WildFire #WinRAR
-
Proof-of-Concept-Exploit für WinRAR-Lücke bringt VenomRAT-Malware mit | heise online
https://heise.de/-9313479 #Cybercrime #Malware #VenomRAT #WinRAR -
Unit42: Fake CVE-2023-40477 Proof of Concept Leads to VenomRAT https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/ #AdvancedURLFiltering #remotecodeexecution #RemoteAccessTrojan #socialengineering #CVE-2023-25157 #CVE-2023-40477 #ProofofConcept #Vulnerability #VenomRAT #WildFire #WinRAR
-
Unit42: Fake CVE-2023-40477 Proof of Concept Leads to VenomRAT https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/ #AdvancedURLFiltering #remotecodeexecution #RemoteAccessTrojan #socialengineering #CVE-2023-25157 #CVE-2023-40477 #ProofofConcept #Vulnerability #VenomRAT #WildFire #WinRAR
-
Unit42: Fake CVE-2023-40477 Proof of Concept Leads to VenomRAT https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/ #AdvancedURLFiltering #remotecodeexecution #RemoteAccessTrojan #socialengineering #CVE-2023-25157 #CVE-2023-40477 #ProofofConcept #Vulnerability #VenomRAT #WildFire #WinRAR
-
Unit42: Fake CVE-2023-40477 Proof of Concept Leads to VenomRAT https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/ #AdvancedURLFiltering #remotecodeexecution #RemoteAccessTrojan #socialengineering #CVE-2023-25157 #CVE-2023-40477 #ProofofConcept #Vulnerability #VenomRAT #WildFire #WinRAR
-
Unit42: Fake CVE-2023-40477 Proof of Concept Leads to VenomRAT https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/ #AdvancedURLFiltering #remotecodeexecution #RemoteAccessTrojan #socialengineering #CVE-2023-25157 #CVE-2023-40477 #ProofofConcept #Vulnerability #VenomRAT #WildFire #WinRAR
-
Unit42: Fake CVE-2023-40477 Proof of Concept Leads to VenomRAT https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/ #AdvancedURLFiltering #remotecodeexecution #RemoteAccessTrojan #socialengineering #CVE-2023-25157 #CVE-2023-40477 #ProofofConcept #Vulnerability #VenomRAT #WildFire #WinRAR
-
Unit42: Fake CVE-2023-40477 Proof of Concept Leads to VenomRAT https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/ #AdvancedURLFiltering #remotecodeexecution #RemoteAccessTrojan #socialengineering #CVE-2023-25157 #CVE-2023-40477 #ProofofConcept #Vulnerability #VenomRAT #WildFire #WinRAR