Golden Chickens MaaS Resurfaces with Four New Malware Families
The Golden Chickens malware-as-a-service operation has re-emerged with four new malware families, including TinyEgg and ChonkyChicken, indicating continued development and modularization by threat actors.

The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, demonstrating a continued commitment to their operations despite extensive public disclosures. The newly identified families are TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and a modified web browser credential theft utility dubbed ChromEggscalator. Recorded Future's Insikt Group, tracking the group as TAG-195, notes that this resurgence signifies an ongoing evolution in the threat actors' toolkit and operational strategies.
TAG-195 is identified as a financially motivated MaaS developer whose tools have previously been linked to TAG-127, both as an operator and a customer. TAG-127 has been observed deploying TinyEgg through social engineering campaigns, often using ClickFix-style lures to trick users into manually executing malicious commands. The introduction of these four new families represents a significant architectural transition and evolution within the TAG-195 MaaS ecosystem. All the new families share common traits, including consistent command-and-control mechanisms, a unified approach to persistence, string obfuscation techniques, and the same delivery model.
TinyEgg serves as a lightweight initial-access backdoor, providing essential functions such as host profiling, interactive shell access, and persistence management. Building upon TinyEgg's capabilities, ChonkyChicken is a more fully featured implant. It expands its functionality to include browser credential theft, live browser session control via the Chrome DevTools Protocol (CDP), credential-backed remote execution, network reconnaissance, and sustained surveillance. This tiered approach allows for initial access and reconnaissance before deploying more potent tools.
The modularized version of ChonkyChicken introduces a sophisticated controller-and-plugin architecture. This design enables the controller to dynamically request and load specific capability modules on demand, rather than embedding all functionalities within a single, monolithic implant. This modular approach significantly enhances defense evasion by reducing the static detection footprint of the base implant and allows for greater flexibility in provisioning capabilities to operators.
ChromEggscalator is presented as a successor to TerraStealerV2 and is a modified version of the publicly available Chrome encryption-bypass tool, ChromElevator. This indicates a focus on enhancing credential theft capabilities, particularly from web browsers, which are often a rich source of sensitive user information. The shift towards modular, operator-driven tooling is a deliberate strategy by Golden Chickens, also known as Venom Spider, to refine its arsenal and improve its ability to evade detection.
The modular ChonkyChicken variant supports 14 distinct components that can be fetched from the C2 infrastructure as needed. These modules cover a wide range of post-exploitation activities, including process management, screen capture, file manipulation, command execution, network and domain reconnaissance, clipboard capture, keylogging, audio capture, idle time checking, and HTTP/S requests. Notably, it also includes a module for browser theft via ChromEggscalator and persistence management, highlighting a comprehensive suite of tools.
One of the 14 modules is named "wtrack," though its specific purpose remains unknown, suggesting ongoing development and the potential for new capabilities to be added. The transition to a modular architecture is likely driven by commercial incentives inherent to the MaaS model. It allows TAG-195 to selectively provision capabilities to its customers, limit exposure if a specific customer or module is compromised, and cater to a broader spectrum of operational requirements, making the service more attractive and adaptable.
The Golden Chickens MaaS ecosystem has a history of being utilized by various cybercrime groups, including Cobalt Group, Evilnum, and FIN6. The continued development and modularization of its toolkit by TAG-195 underscore the persistent threat posed by this operation and its customers. The focus on modularity and defense evasion suggests a strategic effort to maintain operational effectiveness against evolving security measures.
The ChonkyChicken malware, detailed in this report, represents a significant evolution within the TAG-195 (Golden Chickens/Venom Spider) MaaS ecosystem. It introduces advanced capabilities for stealing Chrome credentials via a specialized helper tool, controlling active browser sessions, and enabling sophisticated lateral movement beyond what was previously described for the group.