VenomKit

Description

(Proofpoint) We use this name to describe documents generated by a builder purchased from the same seller as Taurus builder. Depending on the variant it may exploit CVE-2017-0199, CVE-2017-8570, CVE-2017-8759, CVE-2017-11882, CVE-2018-0802, and/or CVE-2018-8174. Notably, VenomKit often also uses the same CMSTP bypass as Taurus Loader.

Names

Name
VenomKit

Category

Malware

Type

  • Loader

Information

Other Information

Uuid

7ba478cd-6fa7-44ad-a08d-1fb2a8604185

Last Card Change

2020-07-10