Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Google Releases Patches for 370 Vulnerabilities in Chrome 151

July 30, 2026

Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

July 30, 2026

NCSC Publishes Guidance to Aid Incident Response and Recovery

July 30, 2026
Facebook X (Twitter) Instagram
Thursday, July 30
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
News

Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

Team-CWDBy Team-CWDJuly 30, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings.

The malware families in question are: TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and a modified web browser credential theft utility codenamed ChromEggscalator. Recorded Future’s Insikt Group is tracking the group under the moniker TAG-195.

TAG-195 is a financially motivated malware-as-a-service (MaaS) developer whose tooling has been previously linked to TAG-127 as an operator and customer. The threat intelligence company said it has also observed TAG-127 deploying TinyEgg via ClickFix-style social engineering campaigns that trick unsuspecting users into manually executing malicious commands.

“The four new families indicate an architectural transition and evolution in the TAG-195 MaaS ecosystem,” Recorded Future said. “All four families share a common set of architectural traits: consistent command-and-control mechanisms, a shared persistence approach, string obfuscation, and execution via the same delivery model.”

A brief description of each of the tools is as follows –

  • TinyEgg, a lightweight initial-access backdoor providing host profiling, interactive shell access, and persistence management
  • ChonkyChicken, a fully featured implant that expands on TinyEgg with browser credential theft, live browser session control using Chrome DevTools Protocol (CDP), credential-backed remote execution, network reconnaissance, and sustained surveillance
  • A modularized version of ChonkyChicken that introduces a controller-and-plugin architecture that enables the controller to request and load 14 discrete capability modules on demand instead of embedding the entire functionality in the implant
  • ChromEggscalator, a successor to TerraStealerV2 and a modified version of a publicly available Chrome encryption-bypass tool called ChromElevator

The shift is a sign that Golden Chickens, also called Venom Spider, is actively refining its arsenal through active development, while deliberately moving to modular, operator-driven tooling for defense evasion.

Associated with a malware family called More_eggs, the threat actor’s tools have been put to use by other cybercrime groups like Cobalt Group (aka Cobalt Gang), Evilnum, and FIN6. Another threat actor associated with the Golden Chickens MaaS is TAG-127, which uses ClickFix or VenomLNK as delivery methods.

Attack chains have been found to leverage ClickFix lures to execute OCX payloads downloaded from attacker-controlled staging infrastructure, resulting in the installation of TinyEgg. The malware’s functionality is limited to initial access and profiling functions, with all post-exploitation capability passed on to ChonkyChicken. TinyEgg is also designed to terminate execution if sandbox and automated analysis environments are detected.

The malware establishes connections with a C2 server using WebSockets to facilitate an interactive command shell, run operator-supplied input to the active shell session commands, send the output back to the controller, and stage OCX payloads.

The modular version of ChonkyChicken, on the other hand, supports 14 different components that are fetched from the C2 infrastructure as needed, allowing the operators to selectively deliver certain functionality on the fly that monolithic malware architectures cannot easily support without an update mechanism. The 14 modules enable the following functions –

  • Process management
  • Screen capture and monitor enumeration
  • File manipulation
  • Command execution
  • Network reconnaissance
  • Domain-based reconnaissance
  • Clipboard capture
  • Keylogging
  • Audio capture
  • Idle time check
  • HTTP/S request via host
  • Browser theft via ChromEggscalator
  • Persistence management

The modular version also supports a module named “wtrack” whose purpose remains unknown. This suggests the addition of an active capability under development.

“TAG-195’s transition to a modular architecture almost certainly reduces the base implant’s static detection exposure, and likely also reflects commercial incentives inherent to the MaaS model, including the ability to provision capabilities selectively to operators, limit exposure if a customer is compromised, and serve a broader range of operational requirements,” the cybersecurity company said.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleNCSC Publishes Guidance to Aid Incident Response and Recovery
Next Article Google Releases Patches for 370 Vulnerabilities in Chrome 151
Team-CWD
  • Website

Related Posts

News

Google Releases Patches for 370 Vulnerabilities in Chrome 151

July 30, 2026
News

NCSC Publishes Guidance to Aid Incident Response and Recovery

July 30, 2026
News

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

July 30, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Why children’s data is a long-term identity risk

June 3, 2026

Here’s what you should know

February 6, 2026

How cybercriminals are targeting content creators

November 26, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.