Golden Chickens MaaS Operators Unleash Four New Malware Families, Evolving Tactics
The notorious **Golden Chickens** malware-as-a-service (MaaS) ecosystem has resurfaced with a significant architectural shift, introducing four new malware families. Despite extensive public disclosures, the financially motivated threat actors, tracked as **TAG-195** by **Recorded Future**, continue to refine their arsenal, signaling a deliberate move towards modular and evasive tooling.
The operators behind the **Golden Chickens** MaaS, also known as **Venom Spider**, are showing no signs of slowing down. Threat intelligence firm **Recorded Future**'s **Insikt Group** has identified a major evolution in their capabilities, with the deployment of four new malware families:
* **TinyEgg**
* **ChonkyChicken**
* A modularized variant of **ChonkyChicken**
* **ChromEggscalator**
This development indicates a strategic architectural transition within the **TAG-195** MaaS ecosystem.

### Shared Characteristics and Delivery Mechanisms
All four new malware families exhibit a consistent set of architectural traits, including common command-and-control (C2) mechanisms, a shared persistence approach, string obfuscation, and execution via the same delivery model. **TAG-195**'s tooling has previously been linked to **TAG-127**, a customer and operator observed deploying **TinyEgg** via **ClickFix**-style social engineering campaigns. These campaigns trick users into manually executing malicious commands.
### A Closer Look at the New Malware Families
**TinyEgg** serves as a lightweight initial-access backdoor. It provides host profiling capabilities, interactive shell access, and persistence management. Notably, **TinyEgg** is designed to terminate execution if sandbox or automated analysis environments are detected, a common evasion technique.
**ChonkyChicken** is a more fully featured implant. It expands on **TinyEgg**'s capabilities with browser credential theft, live browser session control using **Chrome DevTools Protocol (CDP)**, credential-backed remote execution, network reconnaissance, and sustained surveillance.
### The Modular Evolution
A significant leap is the modularized version of **ChonkyChicken**. This variant introduces a controller-and-plugin architecture, allowing the controller to request and load 14 discrete capability modules on demand. This contrasts with monolithic malware architectures that embed all functionality, offering greater flexibility and defense evasion.
**ChromEggscalator** is the successor to **TerraStealerV2**. It's a modified version of **ChromElevator**, a publicly available **Chrome** encryption-bypass tool, designed for web browser credential theft.

### Enhanced Evasion and Commercial Incentives
This shift to a modular architecture almost certainly reduces the base implant's static detection exposure. It also reflects commercial incentives inherent to the MaaS model, enabling **TAG-195** to provision capabilities selectively to operators, limit exposure if a customer is compromised, and serve a broader range of operational requirements.
Associated with the **More_eggs** malware family, **Golden Chickens**' tools have been leveraged by other prominent cybercrime groups such as **Cobalt Group** (aka **Cobalt Gang**), **Evilnum**, and **FIN6**. **TAG-127** also utilizes **ClickFix** or **VenomLNK** as delivery methods.
### Detailed Modular Capabilities
The modular version of **ChonkyChicken** supports a wide array of functions fetched from the C2 infrastructure as needed. These include:
* Process management
* Screen capture and monitor enumeration
* File manipulation
* Command execution
* Network reconnaissance
* Domain-based reconnaissance
* Clipboard capture
* Keylogging
* Audio capture
* Idle time check
* HTTP/S request via host
* Browser theft via **ChromEggscalator**
* Persistence management
Additionally, an unknown module named "wtrack" suggests an active capability still under development, highlighting the ongoing evolution of **TAG-195**'s sophisticated MaaS offerings.