The record
Written from the 1 report below. Nothing here is unsourced.
- The Golden Chickens malware-as-a-service group, tracked as TAG-195, has released four new malware families: TinyEgg, ChonkyChicken, a modular ChonkyChicken variant, and ChromEggscalator.
- The new tools follow a shared architecture with common command-and-control mechanisms, persistence methods, and string obfuscation, and are delivered via ClickFix-style social engineering tricks that make users run malicious commands themselves.
- The shift to a modular design lets operators download only the capabilities they need, making the malware harder to detect and easier to sell as a service.
- Golden Chickens tools have previously been used by other cybercrime groups including Cobalt Group, Evilnum, and FIN6, so the refresh matters for organizations facing financially motivated attacks.
What to watch next
- Whether the unexplained 'wtrack' module in the modular ChonkyChicken variant is revealed as a new capability under development.
- Further use of TinyEgg and the new families in ClickFix or VenomLNK delivery campaigns by TAG-127 and other customers.
- Possible additional public disclosures or defenses following Recorded Future's reporting on the group's architecture.
Coverage1
1 report
English national1
All filed from India
Named India · ChonkyChicken · ChromEggscalator · ChromElevator · Cobalt Group · Evilnum · FIN6 · Golden Chickens · Recorded Future · TAG-127 · TAG-195 · TinyEgg · Venom Spider
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
