Golden Chickens, also known as Venom Spider and tracked by some vendors as TAG-195, is a financially motivated malware-as-a-service developer and operator associated with the More_eggs ecosystem and newer tooling including TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator. The cluster has also been referred to by aliases including Camouflage Tempest, Skeleton Spider, Storm-0538, TA4557, Gold Franklin, ITG08, and Taal. Public reporting has linked its tooling to downstream use by other financially motivated intrusion groups including FIN6, Cobalt Group, Evilnum, and TAG-127. Golden Chickens specializes in initial-access and post-exploitation malware sold or provided to selected criminal customers. More_eggs is a JavaScript backdoor historically associated with the group. More recent tooling shows an architectural shift toward modular, operator-driven implants intended to reduce static detection exposure and selectively deliver capabilities. TinyEgg functions as a lightweight backdoor for initial access, host profiling, interactive shell access, and persistence management. ChonkyChicken expands capability with browser credential theft, live browser session control, credential-backed remote execution, reconnaissance, surveillance, and modular post-exploitation. The modularized ChonkyChicken variant can load multiple capability modules on demand, including process management, screen capture, keylogging, browser theft, command execution, and persistence functions. ChromEggscalator is a customized browser encryption-bypass helper used to support browser data theft. The ecosystem is associated with social-engineering-heavy delivery, including fake job application and recruiter-themed lures, malicious shortcut-based infection chains, and ClickFix-style campaigns that trick victims into manually executing commands. Reporting also links Golden Chickens activity to abuse of legitimate system binaries, obfuscated scripts, persistence via Registry Run keys, and defense-evasion-oriented tooling design. The group’s malware and delivery chains support credential theft, session hijacking through live browser session control, reconnaissance, persistence, keylogging, and broader post-exploitation activity. Golden Chickens is best characterized as a cybercriminal service provider rather than a nation-state actor. Its dominant motivation is financial gain through malware development and enablement of follow-on intrusions by affiliated or customer threat actors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
53 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
38 malware families attributed to this actor across reporting.
33 additional families tracked in Mallory.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
Carberp has exploited multiple Windows vulnerabilities (CVE-2010-2743, CVE-2010-3338, CVE-2010-4398, CVE-2008-1084) and a .NET Runtime Optimization vulnerability for privilege escalation.
FIN6 ... targeted CVE-2013-3660, CVE-2011-2005, and CVE-2010-4398, all of which could allow local users to access kernel-level privileges.
FIN6 ... targeted CVE-2013-3660, CVE-2011-2005, and CVE-2010-4398, all of which could allow local users to access kernel-level privileges.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
The following analytic detects when su runs from a page-cache-corrupted binary... This activity is significant because it indicates a possible privilege escalation attempt, allowing a user to gain root access... CVE CVE-2026-31431 ... References ... copy-fail-CVE-2026-31431
1 more CVE tied to this actor tracked in Mallory.
101 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison point for GoldenEyeDog’s sophistication.
Operators behind the Golden Chickens malware-as-a-service ecosystem resurfaced with four new malware families and are evolving toward modular, operator-driven tooling for initial access, credential theft, browser session control, keylogging, screen capture, and other post-exploitation capabilities.
Financially motivated malware-as-a-service developer resurfacing with four new malware families and transitioning to modular, operator-driven tooling for defense evasion and selective capability delivery.
Mentioned as a criminal group previously linked in public reporting to TAG-195 tooling.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.