The threat actors operating the Golden Chickens malware-as-a-service (MaaS) ecosystem have introduced four new malware families. This expansion includes TinyEgg, ChonkyChicken, a modularized version of ChonkyChicken, and ChromEggscalator. This activity suggests ongoing development despite previous public disclosures about their operations.
TinyEgg is a lightweight initial-access backdoor that provides host profiling, interactive shell access, and persistence management. ChonkyChicken is a more comprehensive implant, adding browser credential theft, live browser session control via Chrome DevTools Protocol (CDP), credential-backed remote execution, network reconnaissance, and sustained surveillance. A modular variant of ChonkyChicken introduces a controller-and-plugin architecture, allowing on-demand loading of 14 discrete capability modules. ChromEggscalator is a modified version of a publicly available Chrome encryption-bypass tool, succeeding TerraStealerV2.
Recorded Future's Insikt Group, tracking the group as TAG-195, notes that these new families signify an architectural transition within the MaaS ecosystem. All four families share common traits such as consistent command-and-control mechanisms, a shared persistence approach, string obfuscation, and a unified delivery model. This shift indicates Golden Chickens, also known as Venom Spider, is actively refining its tools and moving towards modular, operator-driven tooling to evade defenses.
TAG-195 is a financially motivated MaaS developer whose tools have been linked to TAG-127, an operator and customer. TAG-127 has deployed TinyEgg through ClickFix-style social engineering campaigns. The tools associated with the More_eggs malware family have been utilized by other cybercrime groups, including Cobalt Group (aka Cobalt Gang), Evilnum, and FIN6.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The Golden Chickens malware-as-a-service (MaaS) ecosystem has released four new malware families: TinyEgg, ChonkyChicken, a modular ChonkyChicken variant, and ChromEggscalator. This development indicates an architectural shift towards modular, operator-driven tooling for defense evasion, impacting organizations targeted by financially motivated threat actors.