Golden Chickens, also tracked as TAG-195 and Venom Spider, is a financially motivated malware-as-a-service developer and operator ecosystem that supplies intrusion tooling to multiple criminal customers. The group is associated with modular Windows malware used across the intrusion lifecycle, including initial access, persistence, credential theft, browser session abuse, reconnaissance, lateral movement, remote execution, surveillance, and data exfiltration. Public reporting has linked Golden Chickens tooling to financially motivated threat groups including FIN6, Cobalt Group, Evilnum, and TAG-127. The ecosystem includes malware families such as TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator. TinyEgg functions as a lightweight initial-access backdoor with host profiling, shell access, and persistence management. ChonkyChicken is a second-stage or post-exploitation implant designed to turn a compromised Windows endpoint into a platform for broader enterprise compromise. It supports browser credential theft, session hijacking through browser automation, credential-backed and token-backed remote execution, host and network discovery, share enumeration, port scanning, scheduled-task creation, and sustained monitoring of victim activity. Surveillance features include keylogging, clipboard capture, screenshot collection, and audio recording. A notable capability in this ecosystem is theft and abuse of authenticated browser state. ChonkyChicken can automate live Chrome and Edge sessions through Chrome DevTools Protocol to interact with already authenticated business services, while ChromEggscalator is used to bypass Chrome App-Bound Encryption protections and extract protected browser secrets. The malware family also supports optional traffic-interception workflows and uses modular plugin delivery to selectively load capabilities on demand, reducing static footprint and enabling operator-directed deployment. Across its malware families, Golden Chickens shows a consistent development framework characterized by OCX-packaged payloads, execution through legitimate Windows COM registration mechanisms, WebSocket-based command and control, JSON tasking, string obfuscation or encryption, filename-gating checks, and persistence via Windows Run keys. The architecture indicates a mature criminal service model focused on supplying adaptable post-compromise tooling to financially motivated operators.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
41 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates a malware-as-a-service ecosystem supplying tooling to financially motivated criminal operators. In the described campaigns, TAG-195 uses ClickFix lures to deliver TinyEgg and then the ChonkyChicken second-stage implant for credential theft, surveillance, remote execution, reconnaissance, persistence, and lateral movement.
Financially motivated malware-as-a-service developer evolving its tooling with new modular malware families including TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator.
Developer/operator behind a malware-as-a-service ecosystem including TinyEgg, ChonkyChicken, Modular ChonkyChicken, and ChromEggscalator, focused on post-compromise operations such as credential theft, browser credential extraction, surveillance, network reconnaissance, persistence, and lateral movement through modular OCX-based tooling executed via regsvr32 and WebSocket C2.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.