HackMyIP
← Back to News
2026-07-24 The Hacker News

Golden Chickens MaaS Unveils 4 New Malware Families Targeting Browsers

MalwareThreat IntelAPT

The operators behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families—TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and ChromEggscalator—signaling continued active development despite extensive public scrutiny. Tracked by Recorded Future's Insikt Group as TAG-195 (also known as Venom Spider), the financially motivated MaaS developer has historically supplied tooling to affiliates including TAG-127, Cobalt Group (Cobalt Gang), Evilnum, and FIN6. The group's original More_eggs backdoor has been a staple in these operations for years, and the new families suggest a deliberate pivot toward modular, operator-driven architectures designed to complicate detection and forensic analysis.

According to Insikt Group, all four families share a common architectural foundation: consistent command-and-control mechanisms, identical persistence routines, shared string obfuscation techniques, and the same delivery model. TinyEgg functions as a lightweight initial-access backdoor with host profiling, interactive shell access, and persistence management capabilities. ChonkyChicken builds on that foundation with a full-featured implant that adds browser credential theft, live browser session control via the Chrome DevTools Protocol (CDP), credential-backed remote execution, network reconnaissance, and sustained surveillance. Organizations concerned about browser-based data exposure can run a browser fingerprint test to evaluate how identifiable their browser configurations are to trackers and malicious scripts.

The modularized version of ChonkyChicken introduces a controller-and-plugin architecture that allows the operator to request and load 14 discrete capability modules on demand, rather than embedding all functionality into a single monolithic implant. ChromEggscalator serves as the successor to TerraStealerV2 and is a modified version of a publicly available Chrome encryption-bypass tool called ChromElevator, focused on web browser credential theft. Given the emphasis on credential harvesting in this ecosystem, users should routinely verify their credentials using a password checker to identify compromised accounts. TAG-127 has been observed deploying TinyEgg via ClickFix-style social engineering lures that trick users into manually executing malicious commands, with post-exploitation operations handed off to ChonkyChicken.

The evolution of Golden Chickens' arsenal underscores how mature MaaS providers continuously refactor their tooling to evade defenses while maintaining operational consistency for affiliates. The shared architectural traits across the four families—particularly the standardized C2 framework and persistence approach—create detection opportunities for defenders familiar with prior More_eggs activity. Security teams are advised to monitor for ClickFix delivery patterns, unusual OCX payload execution, and anomalous Chrome DevTools Protocol activity. Proactive exposure assessment, including running a DNS leak test to verify that network traffic is not being silently redirected through attacker-controlled infrastructure, remains a practical defensive measure against the surveillance and reconnaissance capabilities baked into this MaaS ecosystem.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →