Golden Chickens, also known as Venom Spider and tracked here as TAG-195, is a financially motivated malware-as-a-service developer associated with a long-running criminal tooling ecosystem used by multiple intrusion operators. The actor is best known for developing and maintaining modular malware used for initial access, post-exploitation, credential theft, reconnaissance, lateral movement, and surveillance in enterprise environments. Reporting has linked Golden Chickens tooling to several financially motivated threat groups, including FIN6, Cobalt Group, Evilnum, and TAG-127, indicating that the actor functions primarily as a supplier serving distinct customers rather than as a single intrusion operator. Golden Chickens has evolved its ecosystem toward a more modular, operator-driven architecture. Malware families associated with this actor include TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator. TinyEgg operates as a lightweight initial-access backdoor that supports host profiling, interactive shell access, and persistence management. ChonkyChicken is a more capable post-compromise implant designed for browser credential theft, browser session automation, credential-backed and token-based remote execution, network reconnaissance, share enumeration, and sustained surveillance. Observed surveillance functions include keylogging, clipboard collection, screen capture, audio capture, and monitor topology discovery. The modularized ChonkyChicken branch separates command-and-control, task routing, and capability delivery through a controller-and-plugin model, allowing operators to retrieve and load only the modules needed for a given intrusion. ChromEggscalator is a customized helper component derived from a public Chrome encryption-bypass tool and integrated into the actor’s browser credential theft workflow. Across these malware families, Golden Chickens demonstrates a consistent development framework. Shared traits include WebSocket-based command and control using JSON tasking, common persistence patterns, string obfuscation or encryption, filename-based execution gating, and packaging of components for execution through legitimate Windows COM registration mechanisms. The modular branch further reduces static detection exposure by minimizing the base implant footprint and shifting functionality into on-demand plugins. The ecosystem also retains specialized workflows such as WPAD-related traffic interception support. Golden Chickens malware has been observed in social-engineering-driven delivery chains, including ClickFix-style campaigns in which victims are tricked into manually executing malicious commands under the guise of security verification. The actor’s tooling has also been associated with delivery methods such as VenomLNK. Overall, Golden Chickens is a mature criminal malware supplier whose tooling emphasizes stealth, modularity, selective capability deployment, and broad utility for financially motivated intrusion sets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
40 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated malware-as-a-service developer evolving its tooling with new modular malware families including TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator.
Developer/operator behind a malware-as-a-service ecosystem including TinyEgg, ChonkyChicken, Modular ChonkyChicken, and ChromEggscalator, focused on post-compromise operations such as credential theft, browser credential extraction, surveillance, network reconnaissance, persistence, and lateral movement through modular OCX-based tooling executed via regsvr32 and WebSocket C2.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.