TAG-127 is a financially motivated cybercriminal threat actor associated with the Golden Chickens malware-as-a-service ecosystem, also tracked through the developer cluster TAG-195 and widely linked to the Golden Chickens and Venom Spider tooling lineage. TAG-127 has been observed as an operator and customer of this ecosystem, deploying TinyEgg through ClickFix-style social-engineering campaigns and also using VenomLNK as a delivery method. TAG-127 intrusion chains rely on user execution of malicious commands presented through fake security verification lures. These campaigns deliver TinyEgg as a lightweight initial-access backdoor, after which broader post-exploitation capability can be handed off to later-stage Golden Chickens tooling such as ChonkyChicken. TinyEgg supports host profiling, interactive shell access, and persistence management, enabling operators to establish and maintain footholds before deploying more capable implants. Activity associated with TAG-127 and the related Golden Chickens tooling demonstrates capabilities spanning initial access, persistence, credential theft, session hijacking, reconnaissance, lateral movement, post-exploitation, defense evasion, keylogging, and exfiltration. The associated tooling has been documented stealing browser credentials, bypassing Chrome protections through ChromEggscalator, manipulating authenticated browser sessions through Chrome DevTools Protocol automation, conducting network and domain reconnaissance, creating remote scheduled tasks, scanning ports, identifying accessible network shares, and collecting keystrokes, clipboard data, screenshots, and audio recordings. The malware ecosystem also uses string obfuscation, filename-based execution gating, abuse of legitimate Windows utilities for payload execution, and Run key persistence. TAG-127 should be understood as part of a broader financially motivated criminal ecosystem rather than a nation-state actor. Its observed tradecraft is consistent with access operations intended to support downstream fraud, account compromise, and broader network intrusion using modular malware supplied by Golden Chickens/Venom Spider.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as the operator associated with ClickFix lure infrastructure sharing an IP address with infrastructure discussed in the report.
Operator/customer associated with the Golden Chickens MaaS ecosystem that deploys TinyEgg using ClickFix or VenomLNK delivery methods.
Threat group tracked as an operator and customer of TAG-195 MaaS tooling, observed deploying TinyEgg through ClickFix-style delivery campaigns.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.