TerraStealer is a Windows credential-stealing malware module associated with the Golden Chickens malware-as-a-service ecosystem, also tracked as Venom Spider, and has been used in operations linked to groups including Evilnum. It is designed to harvest sensitive data from victim systems, particularly credentials and email-related information from web browsers, email clients, and file-transfer utilities, and to exfiltrate that data to attacker-controlled infrastructure. Within the broader Golden Chickens toolchain, TerraStealer functions as a modular theft component alongside other modules used for loading, remote access, TeamViewer abuse, and ransomware deployment.
TerraStealer has been observed delivered as part of socially engineered intrusion chains, especially employment- and resume-themed lures, often involving malicious shortcut files and intermediate loader components such as TerraLoader or VenomLNK. In Evilnum-linked activity, related lures have also impersonated Know Your Customer documentation and other financial paperwork. The malware is part of targeted intrusion activity against organizations in sectors such as financial technology, e-commerce, and other enterprises of interest to financially motivated actors.
A newer variant, TerraStealerV2, appeared in 2025 and expanded collection to Chrome browser credential stores, cryptocurrency wallet data, and browser extension data. That variant used trusted Windows utilities for execution and evasion, performed basic anti-analysis checks, gathered host-identifying information, attempted to unlock browser databases by terminating browser processes, and exfiltrated stolen data through external messaging and file-transfer services. Reporting indicates this newer branch did not bypass Chrome Application Bound Encryption on updated systems, limiting password decryption effectiveness on fully patched hosts. Overall, TerraStealer is best understood as a modular infostealer family used in financially motivated access and theft operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Among the tools used by the Evilnum group are More_eggs, TerraPreter, TerraStealer, and TerraTV.
Venom Spider, also known as GOLDEN CHICKENS, is a threat actor known for offering Malware-as-a-Service (MaaS) tools like VenomLNK, TerraLoader, TerraStealer, and TerraCryptor.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential-harvesting stealer in the Golden Chickens malware suite (distinct from TerraStealerV2), used for credential theft as part of their MaaS offering.
A credential/data stealing malware tool from the Golden Chickens set that the content states was used by Evilnum.
A credential/data theft tool from the Golden Chickens toolset observed in Evilnum operations.
Information-stealing module in the more_eggs suite used to collect and exfiltrate sensitive victim data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.