← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Golden Chickens Malware-as-a-Service Introduces Four New Malware Families

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Golden Chickens (TAG-195) released four new malware families.
  • New families include TinyEgg, ChonkyChicken, modular ChonkyChicken, and ChromEggscalator.
  • The new tools feature consistent C2, shared persistence, and string obfuscation.
  • This represents an architectural shift towards modular, operator-driven tooling.

Golden Chickens Expands Malware Arsenal

The threat actors operating the Golden Chickens malware-as-a-service (MaaS) ecosystem have introduced four new malware families. This expansion includes TinyEgg, ChonkyChicken, a modularized version of ChonkyChicken, and ChromEggscalator. This activity suggests ongoing development despite previous public disclosures about their operations.

New Malware Family Details

TinyEgg is a lightweight initial-access backdoor that provides host profiling, interactive shell access, and persistence management. ChonkyChicken is a more comprehensive implant, adding browser credential theft, live browser session control via Chrome DevTools Protocol (CDP), credential-backed remote execution, network reconnaissance, and sustained surveillance. A modular variant of ChonkyChicken introduces a controller-and-plugin architecture, allowing on-demand loading of 14 discrete capability modules. ChromEggscalator is a modified version of a publicly available Chrome encryption-bypass tool, succeeding TerraStealerV2.

Architectural Evolution and Impact

Recorded Future's Insikt Group, tracking the group as TAG-195, notes that these new families signify an architectural transition within the MaaS ecosystem. All four families share common traits such as consistent command-and-control mechanisms, a shared persistence approach, string obfuscation, and a unified delivery model. This shift indicates Golden Chickens, also known as Venom Spider, is actively refining its tools and moving towards modular, operator-driven tooling to evade defenses.

Connections to Other Cybercrime Groups

TAG-195 is a financially motivated MaaS developer whose tools have been linked to TAG-127, an operator and customer. TAG-127 has deployed TinyEgg through ClickFix-style social engineering campaigns. The tools associated with the More_eggs malware family have been utilized by other cybercrime groups, including Cobalt Group (aka Cobalt Gang), Evilnum, and FIN6.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~15 min · 15 stories · Jul 24

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The Golden Chickens malware-as-a-service (MaaS) ecosystem has released four new malware families: TinyEgg, ChonkyChicken, a modular ChonkyChicken variant, and ChromEggscalator. This development indicates an architectural shift towards modular, operator-driven tooling for defense evasion, impacting organizations targeted by financially motivated threat actors.