Recorded Future Reveals New Malware Families Linked To Golden Chickens Operations

Published:

Recorded Future Insikt Group has identified four new malware families linked to the Golden Chickens malware as a service ecosystem, indicating that the financially motivated cybercrime operation continues to expand its capabilities despite years of public analysis. The newly identified malware includes TinyEgg, ChonkyChicken, a modular version of ChonkyChicken, and ChromEggscalator, a browser credential theft utility. The threat intelligence company tracks the malware developers under the designation TAG 195 and stated that the latest malware reflects a significant architectural evolution focused on modular deployment, improved operational flexibility, and enhanced defense evasion. Researchers also linked TAG 195 to TAG 127, an operator that has been observed using social engineering campaigns to distribute the new malware.

According to Recorded Future, TAG 127 has been deploying TinyEgg through ClickFix style phishing campaigns that persuade victims to manually execute malicious commands. Once installed, TinyEgg functions as a lightweight initial access backdoor capable of profiling compromised systems, providing remote shell access, and maintaining persistence on infected devices. The malware establishes communication with command and control infrastructure using WebSockets, enabling operators to issue commands remotely, execute instructions through an interactive shell, and retrieve execution results from compromised systems. TinyEgg also contains mechanisms to detect sandbox and automated malware analysis environments, allowing it to terminate execution when security research environments are identified. Researchers explained that TinyEgg primarily serves as an entry point into compromised systems, while more advanced post exploitation activities are delegated to the larger ChonkyChicken malware family.

ChonkyChicken significantly expands the available functionality by introducing browser credential theft, remote browser session control using Chrome DevTools Protocol, credential based remote execution, network reconnaissance, and long term surveillance capabilities. Recorded Future also identified a modular version of ChonkyChicken that replaces the traditional monolithic architecture with a controller and plugin framework. Instead of embedding every capability directly within the malware, the controller downloads only the required modules from attacker controlled infrastructure when needed. Researchers identified 14 separate modules supporting functions including process management, screen capture, monitor discovery, file manipulation, command execution, network and domain reconnaissance, clipboard monitoring, keylogging, audio capture, browser credential theft through ChromEggscalator, persistence management, and additional host interaction capabilities. One module named “wtrack” remains under development, suggesting operators are continuing to expand the malware platform. ChromEggscalator itself represents the latest evolution of browser credential theft tools and succeeds TerraStealerV2 while incorporating modifications to a publicly available Chrome encryption bypass utility known as ChromElevator.

Researchers believe the transition toward modular malware provides operational and commercial advantages for the Golden Chickens malware as a service platform. By allowing operators to selectively load only the required components during an intrusion, the malware reduces its static detection footprint while enabling customers to tailor attacks to specific objectives without deploying unnecessary functionality. Recorded Future noted that this approach also limits exposure if a customer infrastructure becomes compromised and allows malware developers to deliver updates more efficiently. Golden Chickens, also known as Venom Spider, has previously been associated with the More_eggs malware family, while its tools have been linked to cybercrime groups including Cobalt Group, Evilnum, and FIN6. Researchers stated that the consistent command and control mechanisms, persistence techniques, string obfuscation methods, and shared delivery approaches observed across the newly discovered malware families demonstrate continued development within the TAG 195 ecosystem as operators refine their malware as a service platform to support increasingly adaptable cybercrime campaigns.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.

Related articles

spot_img