Back to Feed
Threat IntelligenceJul 24, 2026

Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

Golden Chickens MaaS resurfaces with four new malware families and modular implants.

Summary

The Golden Chickens malware-as-a-service (MaaS) ecosystem has reappeared with four new malware families: TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator. These new tools indicate an architectural evolution and a move towards modular, operator-driven tooling for enhanced defense evasion. The group, tracked as TAG-195, is financially motivated and has been linked to other threat actors and cybercrime groups.

Full text

Golden Chickens Resurfaces With Four New Malware Families and Modular Implants Ravie LakshmananJul 24, 2026Threat Intelligence / Browser Security The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings. The malware families in question are: TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and a modified web browser credential theft utility codenamed ChromEggscalator. Recorded Future's Insikt Group is tracking the group under the moniker TAG-195. TAG-195 is a financially motivated malware-as-a-service (MaaS) developer whose tooling has been previously linked to TAG-127 as an operator and customer. The threat intelligence company said it has also observed TAG-127 deploying TinyEgg via ClickFix-style social engineering campaigns that trick unsuspecting users into manually executing malicious commands. "The four new families indicate an architectural transition and evolution in the TAG-195 MaaS ecosystem," Recorded Future said. "All four families share a common set of architectural traits: consistent command-and-control mechanisms, a shared persistence approach, string obfuscation, and execution via the same delivery model." A brief description of each of the tools is as follows - TinyEgg, a lightweight initial-access backdoor providing host profiling, interactive shell access, and persistence management ChonkyChicken, a fully featured implant that expands on TinyEgg with browser credential theft, live browser session control using Chrome DevTools Protocol (CDP), credential-backed remote execution, network reconnaissance, and sustained surveillance A modularized version of ChonkyChicken that introduces a controller-and-plugin architecture that enables the controller to request and load 14 discrete capability modules on demand instead of embedding the entire functionality in the implant ChromEggscalator, a successor to TerraStealerV2 and a modified version of a publicly available Chrome encryption-bypass tool called ChromElevator The shift is a sign that Golden Chickens, also called Venom Spider, is actively refining its arsenal through active development, while deliberately moving to modular, operator-driven tooling for defense evasion. Associated with a malware family called More_eggs, the threat actor's tools have been put to use by other cybercrime groups like Cobalt Group (aka Cobalt Gang), Evilnum, and FIN6. Another threat actor associated with the Golden Chickens MaaS is TAG-127, which uses ClickFix or VenomLNK as delivery methods. Attack chains have been found to leverage ClickFix lures to execute OCX payloads downloaded from attacker-controlled staging infrastructure, resulting in the installation of TinyEgg. The malware's functionality is limited to initial access and profiling functions, with all post-exploitation capability passed on to ChonkyChicken. TinyEgg is also designed to terminate execution if sandbox and automated analysis environments are detected. The malware establishes connections with a C2 server using WebSockets to facilitate an interactive command shell, run operator-supplied input to the active shell session commands, send the output back to the controller, and stage OCX payloads. The modular version of ChonkyChicken, on the other hand, supports 14 different components that are fetched from the C2 infrastructure as needed, allowing the operators to selectively deliver certain functionality on the fly that monolithic malware architectures cannot easily support without an update mechanism. The 14 modules enable the following functions - Process management Screen capture and monitor enumeration File manipulation Command execution Network reconnaissance Domain-based reconnaissance Clipboard capture Keylogging Audio capture Idle time check HTTP/S request via host Browser theft via ChromEggscalator Persistence management The modular version also supports a module named "wtrack" whose purpose remains unknown. This suggests the addition of an active capability under development. "TAG-195's transition to a modular architecture almost certainly reduces the base implant's static detection exposure, and likely also reflects commercial incentives inherent to the MaaS model, including the ability to provision capabilities selectively to operators, limit exposure if a customer is compromised, and serve a broader range of operational requirements," the cybersecurity company said. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Backdoor, browser security, Command and Control, Cybercrime, Information Stealer, Malware, Malware-as-a-Service, Social Engineering, Threat Intelligence ⚡ Top Stories This Week URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code ⭐ Featured Resources What Security Teams Must Defend in the New AI Software Supply Chain Identity Fraud Is Changing Fast. See the Attacks Businesses Face in 2026 What 25 Million Alerts Reveal About the Threats SOCs Ignore How to Find and Control Every Script Running Through Your Marketing Stack Modern SASE Guide: Close the Gaps Traditional Network Security Cannot See

Indicators of Compromise

  • malware — TinyEgg
  • malware — ChonkyChicken
  • malware — ChromEggscalator
  • malware — More_eggs

Entities

TAG-195 (threat_actor)TAG-127 (threat_actor)Cobalt Group (threat_actor)Evilnum (threat_actor)FIN6 (threat_actor)TinyEgg (product)