Golden Chickens is a malware-as-a-service ecosystem operated by the threat cluster also known as Venom Spider. It provides modular malware tooling to financially motivated intrusion actors, including groups such as FIN6 and Cobalt Group, enabling broad criminal use and complicating attribution. The ecosystem is associated with families including More_eggs, TerraStealerV2, TerraLogger, Venom Loader, RevC2, TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator.
Recent Golden Chickens tooling reflects an increasingly modular architecture with shared command-and-control patterns, persistence mechanisms, obfuscation approaches, and delivery models. TinyEgg functions as a lightweight backdoor used for initial access and host profiling, after which more capable implants can be deployed. ChonkyChicken is a more advanced post-exploitation implant that supports browser credential theft and live browser session control. A modularized ChonkyChicken variant uses a controller-and-plugin design that can load capability modules on demand, including process management, screen capture, keylogging, and browser theft functions. ChromEggscalator is described as a modified Chrome encryption-bypass utility used to support browser data access.
The ecosystem’s operator-driven modular design appears intended to improve defense evasion by limiting exposed functionality to only what is needed for a given intrusion, while preserving flexibility for customers of the service. Golden Chickens primarily targets Windows environments and is used in financially motivated operations spanning initial compromise, persistence, credential and session theft, and broader post-exploitation activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Hacker News disclosed that the threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware-as-a-service ecosystem whose operators resurfaced with four new malware families, showing continued development and an evolution toward modular, operator-driven tooling.
A malware toolkit/family referenced in the context of new detection rules, with specific components (TerraLogger and TerraStealerV2) called out for activity-based detection.
Golden Chickens is a financially motivated Eastern European threat actor operating a modular malware-as-a-service (MaaS) platform since at least 2017. They provide modular malware families (More_eggs, TerraStealerV2, TerraLogger, Venom Loader, RevC2) to other cybercrime groups, enabling credential theft, keylogging, remote access, and data exfiltration. Their primary attack vector is spearphishing with malicious LNK files, often disguised as job offers or resumes, targeting financial, retail, industrial, and recruitment sectors. The group is known for advanced evasion techniques and is expected to expand into ransomware and AI-driven automation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.