This report highlights recent activity associated with two threat groups: Venom Spider and APT36. It outlines effective methods for analyzing and tracking their operations using ANY.RUN. The report includes IOCs, TI Lookup queries, adversary profiles, and technical details of the attacks. The analysis also covers malicious samples observed in recent campaigns. The content is intended to support threat hunting and attribution efforts.
A recent blog post by Arctic Wolf describes a campaign attributed to the threat actor Venom Spider, targeting recruitment departments across various industries. The campaign involves the use of phishing emails delivering malicious résumé-themed files that deploy the More_eggs backdoor.
Venom Spider is a financially motivated threat group known for conducting phishing campaigns that deliver the More_eggs backdoor.
Origin: Russia
Active Since: 2017
Motivation: Financial gain
Targeted Countries: USA
Targeted Industries: Financial, Pharmaceutical, Entertainment, Retail, Energy
The first-stage payload in the infection chain used by Venom Spider is a .lnk file containing an obfuscated bat script, delivered to the victim after visiting a phishing site and designed to deploy the More_eggs backdoor.
SHA-256: 33d28cf53f301c3822fac1114a5e33a294f78bd96c3fd632713b10392908bef4
Sample: ANY.RUN
Upon execution of the lnk file, an obfuscated BAT script is launched. This script initiates WordPad to distract the user and creates a file named ieuinit.inf in the %TEMP% directory. The contents of the INF file are obfuscated and are used to construct a URL that points to the next stage of the attack.

In the analyzed sample, the script copies ie4uinit.exe from C:\Windows\System32\ to the %TEMP% directory and executes it with the -basesettings parameter. This causes ie4uinit.exe to process the INF file and initiate a request to the constructed URL to retrieve a JavaScript-based payload responsible for delivering the More_eggs backdoor.
With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.
TI Lookup:
commandLine:"*ieuinit.inf*" and commandLine:"*C:\\Users\\admin\\AppData\\Local\\Temp\\ie4uinit.exe -basesettings*"

As a result of the TI Lookup query, multiple analysis entries were identified that reference different versions of phishing URLs and domains used to deliver ZIP archives containing .lnk payloads. Variants of the .lnk files themselves are also available for review within these results. For example, one of these analyses reveals a phishing page from which a ZIP archive is downloaded, containing a .lnk file that, once executed, ultimately leads to the delivery of the More_eggs dropper.
In this analysis, after ie4uinit.exe is executed, it processes the ieuinit.inf file and reconstructs the URL ssgad.sophia-pascal[.]com, which is then contacted to retrieve the next stage of the payload. The response contains JavaScript code that, once executed, creates a DLL file at C:\Users\admin\AppData\Roaming\Adobe\62442.dll. This DLL serves as the More_eggs dropper.
Following the execution of the More_eggs dropper DLL, several .txt files are created in the user's Roaming\Adobe directory — one containing obfuscated JavaScript code and another acting as a launcher. Additionally, a legitimate copy of msxsl.exe is placed in the same directory and used to execute the JavaScript payload, continuing the infection chain.

Using ANY.RUN's Interactive Sandbox, we can obtain extended visibility into the use of msxsl.exe in this campaign. Specifically, the process is marked as untrusted, exhibits JavaScript activity (captured by Script Tracer), accesses registry settings, and leverages WMI for system information discovery. Based on the observed behavior, relevant MITRE ATT&CK tactics and techniques are mapped to the process, allowing for more accurate classification of the attack stages. This represents only a portion of the behavioral details available through sandbox analysis.
A recent report by Hunt.io outlines a phishing campaign by APT36 (Transparent Tribe), targeting individuals linked to the Indian Ministry of Defence. Victims are lured through fake government-themed sites to execute malicious HTA files on Windows or shell scripts on Linux, leading to the deployment of custom loaders and communication with attacker-controlled infrastructure.
APT36 is a state-sponsored threat group linked to Pakistan, known for cyberespionage campaigns against Indian government and military targets. The group frequently uses phishing emails to deliver custom malware.
Origin: Pakistan
Active Since: 2013
Motivation: Espionage, Information Theft
Targeted Countries: India, Iran, Germany, Afghanistan, USA, Australia, UK, Spain, Netherlands, Canada, Saudi Arabia, Kazakhstan
Targeted Industries: Government, Military, Education, Defense, Aerospace
The threat actors impersonate the Indian Ministry of Defence using the spoofed domain email.gov.in.drdosurvey[.]info. This domain is used to host phishing pages that lead to the execution of malicious payloads through the ClickFix infection technique.
The campaign targets both Windows and Linux users, delivering platform-specific payloads designed to initiate the infection chain.
With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.
TI Lookup:
domainName:"email.gov.in.drdosurvey.info"
A lookup query for the domain email.gov.in.drdosurvey[.]info returns multiple sandbox analyses involving both Windows and Linux environments, confirming the use of platform-specific payloads observed in the ClickFix campaign.
Although the campaign’s second stage is typically initiated via a clipboard-injected command pointing to index.php, our sandbox analysis captures a later phase of the infection chain, where the sysinte.hta file is executed directly via mshta.exe. The process mshta.exe interacts with the domain trade4wealth[.]in to retrieve second-stage payloads. This file contains the malicious logic responsible for the next steps in the compromise.
With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.
TI Lookup:
commandLine:"*mshta.exe*" AND domainName:"trade4wealth.in"
After sysinte.hta is executed, it launches a batch script named noway.bat, which in turn saves a file named zuidrt.pdf to disk at the path C:\Users\Public\USOShared-1de48789-1285\zuidrt.pdf. This file contains malicious code in the form of obfuscated textual content and is launched as a separate process. Immediately after execution, it initiates a series of TCP connections to the IP address 185.117.90[.]212 over the non-standard port 7771, indicating an attempt to establish communication with a remote server.

To achieve persistence on the system, the file is added to the startup via a call to reg.exe, which modifies the following registry key:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
with the value:
cmd /C start C:\Users\Public\USOShared-1de48789-1285\zuidrt.pdf
This report covers two separate cases involving recent activity by the groups Venom Spider and APT36, highlighting IOCs, malware samples, and execution techniques specific to each. Using ANY.RUN, we demonstrated how analysts can investigate such threats and search for related activity. These capabilities help expand understanding of each threat, reveal additional indicators, and support informed defensive actions