● News

Golden Chickens MaaS Operation Returns With Four New Malware Variants

July 24, 2026 · snewle
Golden Chickens MaaS Operation Returns With Four New Malware Variants

The operators behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have returned with four newly developed malware families, demonstrating continued evolution despite extensive public exposure of their operations. Recorded Future’s Insikt Group tracks this financially motivated threat actor as TAG-195, whose tooling has previously been utilized by TAG-127 as both operator and customer.

The four new malware families identified include TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and ChromEggscalator, a modified browser credential theft utility. According to researchers, these families represent an architectural transition in the TAG-195 MaaS ecosystem, sharing common traits including consistent command-and-control mechanisms, shared persistence approaches, string obfuscation, and identical delivery models.

What Are the Capabilities of Each Malware Family?

TinyEgg functions as a lightweight initial-access backdoor providing host profiling, interactive shell access, and persistence management capabilities. The malware establishes connections with command-and-control servers using WebSockets to facilitate interactive command shells and stage OCX payloads. It includes anti-analysis features, terminating execution when sandbox or automated analysis environments are detected.

ChonkyChicken represents a fully featured implant expanding on TinyEgg’s foundation with browser credential theft, live browser session control using Chrome DevTools Protocol, credential-backed remote execution, network reconnaissance, and sustained surveillance capabilities. All post-exploitation functionality is passed from TinyEgg to ChonkyChicken once initial access is established.

How Does the Modular Architecture Function?

The modularized version of ChonkyChicken introduces a controller-and-plugin architecture that enables operators to request and load 14 discrete capability modules on demand rather than embedding complete functionality in the base implant. This approach reduces static detection exposure and reflects commercial incentives inherent to the MaaS model, allowing selective capability provisioning to operators.

The 14 modules enable process management, screen capture and monitor enumeration, file manipulation, command execution, network reconnaissance, domain-based reconnaissance, clipboard capture, keylogging, audio capture, idle time checking, HTTP/S requests via host, browser theft via ChromEggscalator, and persistence management. A module named “wtrack” with unknown purpose suggests an active capability under development.

What Delivery Methods Are Being Used?

Researchers observed TAG-127 deploying TinyEgg through ClickFix-style social engineering campaigns that manipulate unsuspecting users into manually executing malicious commands. Attack chains leverage ClickFix lures to execute OCX payloads downloaded from attacker-controlled staging infrastructure, resulting in TinyEgg installation.

ChromEggscalator represents a successor to TerraStealerV2 and is based on a modified version of a publicly available Chrome encryption-bypass tool called ChromElevator. The shift to modular, operator-driven tooling indicates Golden Chickens, also known as Venom Spider, is actively refining its arsenal through deliberate development focused on defense evasion. The threat actor’s tools, associated with the More_eggs malware family, have historically been utilized by cybercrime groups including Cobalt Group, Evilnum, and FIN6.

Source: The Hacker News