Golden Chickens is a financially motivated cybercrime operation and malware-as-a-service provider best known for developing and operating the More_eggs malware ecosystem. The group is widely tracked under aliases including Venom Spider, TA4557, and Storm-0538. Golden Chickens has supplied tooling to other criminal actors, including FIN6 and Cobalt Group, and has been associated with additional malware families and services such as TerraStealer, TerraPreter, and TerraTV. The actor is known for social-engineering-heavy intrusion chains, especially job-application and human-resources themed lures delivered through archives, shortcut files, and script-based payloads. Campaigns have targeted recruiters and human resources personnel, including direct-email operations observed since at least late 2023. A common pattern is the use of malicious shortcut files and heavily obfuscated command interpreters to launch staged infections while opening decoy documents or images to reduce suspicion. Golden Chickens frequently abuses legitimate Windows utilities and signed binaries for execution and defense evasion, and its delivery chains often culminate in JavaScript-based loaders or backdoors. More_eggs, the group’s flagship malware, is a modular JavaScript backdoor and dropper platform used for initial access, payload retrieval, reconnaissance, and follow-on malware deployment. It has been described as a potent backdoor sold to other threat actors as part of a malware-as-a-service offering. Observed tradecraft includes server-side polymorphism, obfuscated scripts, downloader stages, persistence via common Windows autostart mechanisms, and living-off-the-land execution chains. Golden Chickens operations have also been linked to recruiter-focused malware delivery and to broader financially motivated intrusion activity. The actor should be distinguished from FIN6, although the two are closely connected operationally through tooling use. Golden Chickens is primarily the malware provider and operator behind More_eggs and related services, whereas FIN6 is one of the threat groups known to leverage that tooling in its own campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
35 malware families attributed to this actor across reporting.
30 additional families tracked in Mallory.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
Carberp has exploited multiple Windows vulnerabilities (CVE-2010-2743, CVE-2010-3338, CVE-2010-4398, CVE-2008-1084) and a .NET Runtime Optimization vulnerability for privilege escalation.
FIN6 ... targeted CVE-2013-3660, CVE-2011-2005, and CVE-2010-4398, all of which could allow local users to access kernel-level privileges.
FIN6 ... targeted CVE-2013-3660, CVE-2011-2005, and CVE-2010-4398, all of which could allow local users to access kernel-level privileges.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
The following analytic detects when su runs from a page-cache-corrupted binary... This activity is significant because it indicates a possible privilege escalation attempt, allowing a user to gain root access... CVE CVE-2026-31431 ... References ... copy-fail-CVE-2026-31431
1 more CVE tied to this actor tracked in Mallory.
97 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a comparison point for the sophistication of GoldenEyeDog.
Listed as an annotation/tag associated with privilege escalation techniques in the detection content; no campaign or activity by the group is described in this reference.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
Uses Windows Credential Editor and Metasploit PsExec NTDSGRAB to dump credentials and obtain copies of Active Directory databases.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.