Close Menu
    What's Hot

    ISPS HANDA Women’s Scottish Open: Jenny Shin takes commanding five-shot lead as Charley Hull and Nelly Korda struggle | Golf News

    1.6 Million Egg Cartons Are Recalled Over Salmonella Risk

    In Rush to Track Down Air Force One Leaks, DOJ Reversed Its Own Process

    Facebook X (Twitter) Instagram
    Trending
    • ISPS HANDA Women’s Scottish Open: Jenny Shin takes commanding five-shot lead as Charley Hull and Nelly Korda struggle | Golf News
    • 1.6 Million Egg Cartons Are Recalled Over Salmonella Risk
    • In Rush to Track Down Air Force One Leaks, DOJ Reversed Its Own Process
    • Foreign Leaders Condemn Trump’s ‘Forced Labor’ Tariffs
    • Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
    • Here’s how Meta decides who to lay off—and it claims to not use AI
    • Trump’s Threatened New Front in Iran War Could Strain U.S. Forces
    • One of NASA’s Most Important Deep Space Observatories Hit by Spanish Wildfires
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

    adminBy adminJuly 24, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJul 24, 2026Threat Intelligence / Browser Security

    Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

    The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings.

    The malware families in question are: TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and a modified web browser credential theft utility codenamed ChromEggscalator. Recorded Future’s Insikt Group is tracking the group under the moniker TAG-195.

    TAG-195 is a financially motivated malware-as-a-service (MaaS) developer whose tooling has been previously linked to TAG-127 as an operator and customer. The threat intelligence company said it has also observed TAG-127 deploying TinyEgg via ClickFix-style social engineering campaigns that trick unsuspecting users into manually executing malicious commands.

    “The four new families indicate an architectural transition and evolution in the TAG-195 MaaS ecosystem,” Recorded Future said. “All four families share a common set of architectural traits: consistent command-and-control mechanisms, a shared persistence approach, string obfuscation, and execution via the same delivery model.”

    Cybersecurity

    A brief description of each of the tools is as follows –

    • TinyEgg, a lightweight initial-access backdoor providing host profiling, interactive shell access, and persistence management
    • ChonkyChicken, a fully featured implant that expands on TinyEgg with browser credential theft, live browser session control using Chrome DevTools Protocol (CDP), credential-backed remote execution, network reconnaissance, and sustained surveillance
    • A modularized version of ChonkyChicken that introduces a controller-and-plugin architecture that enables the controller to request and load 14 discrete capability modules on demand instead of embedding the entire functionality in the implant
    • ChromEggscalator, a successor to TerraStealerV2 and a modified version of a publicly available Chrome encryption-bypass tool called ChromElevator

    The shift is a sign that Golden Chickens, also called Venom Spider, is actively refining its arsenal through active development, while deliberately moving to modular, operator-driven tooling for defense evasion.

    Associated with a malware family called More_eggs, the threat actor’s tools have been put to use by other cybercrime groups like Cobalt Group (aka Cobalt Gang), Evilnum, and FIN6. Another threat actor associated with the Golden Chickens MaaS is TAG-127, which uses ClickFix or VenomLNK as delivery methods.

    Attack chains have been found to leverage ClickFix lures to execute OCX payloads downloaded from attacker-controlled staging infrastructure, resulting in the installation of TinyEgg. The malware’s functionality is limited to initial access and profiling functions, with all post-exploitation capability passed on to ChonkyChicken. TinyEgg is also designed to terminate execution if sandbox and automated analysis environments are detected.

    The malware establishes connections with a C2 server using WebSockets to facilitate an interactive command shell, run operator-supplied input to the active shell session commands, send the output back to the controller, and stage OCX payloads.

    Cybersecurity

    The modular version of ChonkyChicken, on the other hand, supports 14 different components that are fetched from the C2 infrastructure as needed, allowing the operators to selectively deliver certain functionality on the fly that monolithic malware architectures cannot easily support without an update mechanism. The 14 modules enable the following functions –

    • Process management
    • Screen capture and monitor enumeration
    • File manipulation
    • Command execution
    • Network reconnaissance
    • Domain-based reconnaissance
    • Clipboard capture
    • Keylogging
    • Audio capture
    • Idle time check
    • HTTP/S request via host
    • Browser theft via ChromEggscalator
    • Persistence management

    The modular version also supports a module named “wtrack” whose purpose remains unknown. This suggests the addition of an active capability under development.

    “TAG-195’s transition to a modular architecture almost certainly reduces the base implant’s static detection exposure, and likely also reflects commercial incentives inherent to the MaaS model, including the ability to provision capabilities selectively to operators, limit exposure if a customer is compromised, and serve a broader range of operational requirements,” the cybersecurity company said.

    chickens Families Golden Implants Malware modular resurfaces
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleHere’s how Meta decides who to lay off—and it claims to not use AI
    Next Article Foreign Leaders Condemn Trump’s ‘Forced Labor’ Tariffs
    admin
    • Website

    Related Posts

    Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

    July 24, 2026

    Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers

    July 24, 2026

    BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

    July 24, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    ISPS HANDA Women’s Scottish Open: Jenny Shin takes commanding five-shot lead as Charley Hull and Nelly Korda struggle | Golf News

    1.6 Million Egg Cartons Are Recalled Over Salmonella Risk

    In Rush to Track Down Air Force One Leaks, DOJ Reversed Its Own Process

    Foreign Leaders Condemn Trump’s ‘Forced Labor’ Tariffs

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by