Golden Chickens is a malware-as-a-service ecosystem operated by the threat actor commonly tracked as Venom Spider and associated with the underground persona badbullzvenom. Active since at least 2018, it provides a modular toolkit to financially motivated intrusion sets including FIN6, Cobalt Group, and Evilnum. The platform is centered on the more_eggs backdoor and loader and has evolved into a broader family of interchangeable implants and plugins designed for targeted enterprise intrusions.
Golden Chickens tooling is primarily associated with Windows environments and commonly uses social-engineering lures for initial compromise, especially job-themed campaigns delivered through fake resumes, fake job offers, and malicious shortcut files. Observed campaigns have also used bank-document-themed lures and targeted corporate employees, hiring managers, and organizations in sectors including financial services, retail, chemical, and e-commerce.
The ecosystem is notable for its modular architecture. Documented components include VenomLNK for user execution and initial access, TerraLoader for loading follow-on plugins, TerraRecon for host and network profiling, TerraStealer for theft of credentials and email data from browsers, email clients, and transfer utilities, TerraLogger for keystroke capture, TerraTV for hijacking active TeamViewer sessions to facilitate lateral movement, TerraPreter for interactive post-exploitation activity including discovery and credential theft, and TerraCrypt as an encryption payload intended for ransomware-style extortion. More recent families linked to the ecosystem include TinyEgg, a lightweight backdoor used for initial access and host profiling; ChonkyChicken, a more capable implant supporting browser credential theft and live browser session control; a modularized ChonkyChicken variant with on-demand plugin loading; and ChromEggscalator, a Chrome encryption-bypass utility.
Golden Chickens emphasizes selective capability deployment, shared command-and-control patterns, persistence mechanisms, and obfuscation across families. This operator-driven modularity supports defense evasion, reduces exposure of the full toolset during individual intrusions, and increases the commercial flexibility of the service for different criminal customers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For the past 16 months, eSentire’s security research team, the Threat Response Unit (TRU) has been tracking one of the most capable and stealthy malware suites — Golden Chickens.
For the past 16 months, eSentire’s security research team, the Threat Response Unit (TRU) has been tracking one of the most capable and stealthy malware suites — Golden Chickens.
For the past 16 months, eSentire’s security research team, the Threat Response Unit (TRU) has been tracking one of the most capable and stealthy malware suites — Golden Chickens.
The Hacker News disclosed that the threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The Cobalt Group's typical MO was to infiltrate banking institutions by sending spear phishing emails with malicious attachments to bank employees.
The Evilnum group is also known to spear phish employees of the companies they are targeting and enclose malicious zip files. If executed, the employees often get hit with the more_eggs backdoor, along with other malware.
The operators then send a link leading to a mock resume PDF through the organization‘s recruitment platform (e.g. Indeed, LinkedIn, or the organization‘s own career web page). The PDF purports to be broken, offering an embedded link to the malicious VenomLNK file on the branding website.
They have also taken great pains to obfuscate the Golden Chickens malware, trying to make it undetectable by most AV companies...
69 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware-as-a-service ecosystem whose operators resurfaced with four new malware families, showing continued development and an evolution toward modular, operator-driven tooling.
A malware toolkit/family referenced in the context of new detection rules, with specific components (TerraLogger and TerraStealerV2) called out for activity-based detection.
Golden Chickens is a financially motivated Eastern European threat actor operating a modular malware-as-a-service (MaaS) platform since at least 2017. They provide modular malware families (More_eggs, TerraStealerV2, TerraLogger, Venom Loader, RevC2) to other cybercrime groups, enabling credential theft, keylogging, remote access, and data exfiltration. Their primary attack vector is spearphishing with malicious LNK files, often disguised as job offers or resumes, targeting financial, retail, industrial, and recruitment sectors. The group is known for advanced evasion techniques and is expected to expand into ransomware and AI-driven automation.
A stealthy modular malware suite sold as Malware-as-a-Service since 2018. It includes components for initial access, backdoor access, loading plugins, reconnaissance, credential and email theft, lateral movement, remote shell access, and ransomware-style encryption. It has been used in targeted campaigns including fake job offers and resume lures.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.