The Golden Chickens cybercrime group has introduced four new modular malware families designed to facilitate credential theft and browser session hijacking. The threat actor, which operates under multiple aliases including TAG-195 and Venom Spider, has demonstrated a significant evolution in its malware-as-a-service operations through these latest releases.
What Are the New Malware Families?
The newly identified malware strains include TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and ChromEggscalator. These four families represent what researchers characterize as a clear architectural evolution in the group’s approach to developing and distributing malicious software. Each family appears designed with modularity in mind, allowing for greater flexibility in post-exploitation activities.
How Do These Threats Target Users?
The malware families focus specifically on stealing credentials from Chrome browsers and hijacking active browser sessions. This targeted approach reflects an understanding of how widely Chrome is used across both enterprise and personal computing environments. By compromising browser sessions, attackers can potentially gain access to authenticated accounts without needing to bypass additional security measures like multi-factor authentication.
What Does This Mean for Malware-as-a-Service?
Golden Chickens operates within the malware-as-a-service ecosystem, meaning these tools are likely being offered to other cybercriminals rather than used exclusively by the group itself. The shift toward modular malware design suggests the group is responding to customer demand for more flexible and customizable attack tools. This architectural change allows affiliates to select specific modules based on their targets and objectives, making the malware more versatile across different attack scenarios.
Understanding the Threat Actor Behind the Campaign
The group’s use of multiple tracking identifiers—Golden Chickens, TAG-195, and Venom Spider—indicates that various security research organizations have been monitoring their activities independently. This level of attention from multiple threat intelligence teams suggests the group has maintained a persistent and notable presence in the cybercrime landscape. Their continued development of new malware families demonstrates ongoing investment in their criminal infrastructure.
The modular nature of these new families marks a departure from previous approaches, indicating that Golden Chickens is adapting its offerings to meet evolving market demands within the underground economy. This evolution in design philosophy could make detection and mitigation more challenging for security teams, as modular malware can be configured differently across various deployments.
Source: GBHackers