Skip to content

Malware

VenomLNK

VenomLNK is the initial phase of the more_eggs malware-as-a-service.

VenomLNK is the initial phase of the more_eggs malware-as-a-service. It is a poisoned .lnk file that depends on User Execution and points to LOLBINs (often cmd.exe) with additional obfuscated scripting options. This typically initiates WMI abuse and TerraLoader, which can load additional functionality through various plugins.


Family metadata imported from Malpedia (Fraunhofer FKIE).