Golden Chickens, also known as Venom Spider and TA4557, is a financially motivated malware-as-a-service operator and developer associated with the More_eggs malware ecosystem. The actor supplies modular tooling to other cybercriminals rather than being known primarily as a standalone intrusion crew, and its malware has been used by groups including FIN6, Cobalt Group, and Evilnum. Public reporting has also linked the operation to the underground persona badbullzvenom. Golden Chickens has specialized in socially engineered initial access, especially recruitment- and resume-themed lures directed at hiring managers, recruiters, and corporate personnel. Campaigns have used fake job applications, fake resumes, recruiter outreach, CAPTCHA-gated download pages, malicious shortcut files, and ClickFix-style user-execution chains. Delivery and execution commonly rely on living-off-the-land techniques and trusted Windows utilities, including script-driven loaders and abuse of native components for stealth. Its malware ecosystem is modular and has evolved over time. Historically associated components include More_eggs as a primary backdoor and loader; VenomLNK for initial execution; TerraLoader for staging plugins; TerraRecon for host and network profiling; TerraStealer for credential and email theft; TerraTV for TeamViewer session hijacking; TerraPreter for interactive post-exploitation; and TerraCrypt as an encryption payload. More recent tooling includes TinyEgg for lightweight initial access and profiling, ChonkyChicken for broader post-exploitation, a modular ChonkyChicken variant with on-demand capability modules, ChromEggscalator for Chrome data access, TerraStealerV2 for browser credential and cryptocurrency-wallet theft, TerraLogger for keylogging, and additional loaders and backdoors reported in the ecosystem. Observed capabilities across the Golden Chickens toolset include initial access, persistence, reconnaissance, credential theft, session hijacking, keylogging, lateral movement, post-exploitation, exfiltration, and defense evasion. The actor’s tooling has supported browser credential theft, live browser session control, host profiling, interactive shell access, screen capture, clipboard capture, audio capture, process management, command execution, and selective module loading. Multiple reports emphasize anti-analysis and anti-sandbox checks, string obfuscation, polymorphism, and modular operator-driven delivery intended to reduce detection and tailor capability exposure to customers. Victimology indicates a focus on organizations with financial value or payment exposure, as well as HR and recruiting functions that can be exploited through employment-themed lures. Reported targets have included financial companies, e-commerce organizations, healthcare technology, and broader corporate environments. Golden Chickens activity is best characterized as cybercrime infrastructure enabling downstream fraud, credential theft, and follow-on intrusions by affiliated or customer threat actors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
19 malware families attributed to this actor across reporting.
14 additional families tracked in Mallory.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operators behind the Golden Chickens malware-as-a-service ecosystem resurfaced with four new malware families and are evolving toward modular, operator-driven tooling for initial access, credential theft, browser session control, keylogging, screen capture, and other post-exploitation capabilities.
Financially motivated malware-as-a-service developer resurfacing with four new malware families and transitioning to modular, operator-driven tooling for defense evasion and selective capability delivery.
Named threat actor referenced in global threat reporting.
Cybercrime group expanding tooling with TerraStealerV2 and TerraLogger to steal browser credentials and cryptocurrency wallet data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.