Ransomware, Malware, Threat Management, Threat Intelligence

Venom Stealer MaaS handles attacks from ClickFix to crypto theft

A new malware-as-a-service (MaaS) infostealer called Venom Stealer facilitates ClickFix attacks that lead to the theft of cryptocurrency and credentials, BlackFog reported Tuesday.

Venom Stealer is offered to vetted cybercriminals for prices starting at $250 a month, or $1,800 for a lifetime license. The web panel enables users to conduct attacks starting from social-engineering templates all the way to the cracking of cryptocurrency wallets and persistence monitoring of browser activity for further credential theft.

The panel includes four different ClickFix templates with a Windows and macOS version for each template. These include a fake Cloudflare CAPTCHA, a fake operating system update, a fake SSL certificate error and fake font installation page, BlackFog said.

The ClickFix pages instruct the victim to run commands in the Windows Run dialog or macOS Terminal, using EXE, PS1, HTA or BAT formats for Windows and bash and curl commands for macOS.

The Venom Stealer payload is a C++ binary that is compiled from the web panel. It targets Chromium and Firefox browsers, extracting data including saved passwords, session cookies, browsing history, autofill data and cryptocurrency wallet vaults, BlackFox described. The infostealer can reportedly bypass Chrome’s v10 and v20 password encryption, allowing passwords to be harvested silently.


Related reading:


“All of this data leaves the infected device immediately, with little or no local staging or delay. Without adequate visibility into outbound traffic, detecting this activity becomes significantly more difficult,” wrote BlackFog CEO and Founder Darren Williams.

Wallet data exfiltrated by Venom Stealer is automatically passed to a wallet-cracking engine, which leverages GPU infrastructure to crack wallets from MetaMask, Phantom, Solflare, Trust Wallet, Atomic, Exodus, Electrum, Bitcoin Core, Monero and Tonkeeper, the researchers report. Funds from cracked wallets are then transferred to the attacker across nine different blockchains.

Venom Stealer persists on the victim’s machine in order to continue monitoring Chrome login data, automatically extracting any new credentials saved to the browser. The MaaS was continually updated throughout March 2026, indicating “full-time,” active development, BlackFog said.

The researchers recommend organizations defend against ClickFix on Windows by restricting PowerShell execution and using Group Policy to disable the use of the Run dialog by standard users.

Monitoring outbound traffic is also key for catching data exfiltration events, as Venom Stealer’s rapid exfiltration methods leave fewer opportunities for detection and response.

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds