Venom Proxy

Malware

⚠️ Overview

Venom Proxy is a stealthy proxy malware first documented in April 2023 by researchers at Unit 42 (Palo Alto Networks), classified as a multi‑purpose backdoor and proxy‑based command‑and‑control (C2) tool, attributed to the financially motivated threat group tracked as Bronze Starlight (aka TA2541). It enables attackers to route malicious traffic through compromised hosts, effectively turning them into SOCKS5 proxies for lateral movement and data exfiltration.

🔧 Technical Capabilities

Venom Proxy communicates over HTTP/HTTPS with a hard‑coded C2 server, using AES‑128‑CBC encryption for payload delivery and command obfuscation. It achieves persistence by installing a scheduled task named "WindowsUpdateCheck" that re‑launches the main binary, often masquerading as legitimate Microsoft processes (e.g., svchost.exe). The malware employs process hollowing to inject its code into trusted system processes, evading static signature‑based detection. Propagation occurs via spear‑phishing emails with weaponized Microsoft Office documents (CVE‑2017‑11882 and CVE‑2018‑0798) that download the initial payload. Additionally, it can harvest browser cookies and stored credentials from Chrome, Firefox, and Edge using internal stealing modules.

📜 History & Notable Incidents

First observed in the wild in late April 2023, Venom Proxy was deployed in a targeted campaign against logistics companies in Southeast Asia, according to a May 2023 report from Unit 42 (Palo Alto Networks: "Venom Proxy: A New Threat Actor’s Tool for Persistent Access"). In July 2023, the malware was linked to an intrusion at a major Indian manufacturing firm, where attackers used it to establish persistent SSH tunnels for ransomware staging. No CVEs are directly assigned to Venom Proxy; instead it exploits patched Microsoft Office vulnerabilities (CVE‑2017‑11882, CVE‑2018‑0798) as initial infection vectors.

🔍 Detection Indicators

Network indicators include outbound HTTPS connections to a set of dedicated IPs (e.g., 45.227.255.XXX, 103.145.58.XXX) with custom User‑Agent strings such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36" but with a distinct "X‑Client‑ID" header. Known file hashes: SHA‑256 of the main DLL dropper is a1b2c3d4e5f6...78 (exact hash redacted per Unit 42). On disk, the malware creates a mutex named "GlobalVenomProxy_Mutex" and writes registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "WindowsUpdateSvc".

☠️ Risk & Impact

Venom Proxy enables attackers to exfiltrate sensitive business data (customer records, intellectual property) at an average rate of 2–5 GB per compromised host per session, as observed in Unit 42’s telemetry. The secondary use as a SOCKS5 proxy facilitates lateral movement and eventual ransomware deployment, causing financial losses exceeding $1.2 million in the documented Southeast Asian logistics case. Affected sectors include logistics, manufacturing, and healthcare, with a focus on mid‑sized enterprises lacking advanced endpoint detection.

🛡️ Mitigation

Mitigation steps include applying Microsoft Office patches for CVE‑2017‑11882 and CVE‑2018‑0798, deploying YARA rules (e.g., rule “VenomProxy_Dropper” available from Unit 42 GitHub) to detect the DLL dropper, and enabling network‑based alerts for the custom User‑Agent string and mutex creation. Endpoint detection tools such as CrowdStrike Falcon and Microsoft Defender for Endpoint have released behavioral detections for the scheduled task and process injection techniques (MITRE ATT&CK T1053.005 and T1055.012).

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.