TerraRecon is a Windows reconnaissance tool associated with the Golden Chickens malware-as-a-service ecosystem, also tracked in connection with the Venom Spider threat actor. It has been observed in highly targeted intrusions at least from 2016 through 2018 and is assessed to have existed as early as 2013. TerraRecon is used after initial compromise, likely as a second- or third-stage component, to profile infected systems and gather environmental information useful for follow-on operations. Its functionality includes scanning compromised hosts for specific hardware and software, particularly technologies associated with retail and money-transfer environments, including Western Union-related software, Wacom signature devices, and YubiKey hardware tokens. This behavior indicates a role in victim validation and operational targeting rather than broad commodity deployment. Within the broader Golden Chickens toolchain, TerraRecon complements other modular components used for loading, credential theft, lateral movement, and extortion, and has been linked to campaigns attributed to financially motivated operators that have targeted organizations handling payments and related financial workflows.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Additional malware families attributed to the Golden Chickens ecosystem include TerraRecon for reconnaissance, TerraWiper for data wiping, and lite_more_eggs...
2 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
"Related Families: VenomLNK, TerraLoader, TerraStealer, TerraTV, TerraCrypt, TerraRecon, TerraWiper, lite_more_eggs, RevC2, Venom Loader"
Reconnaissance module attributed to Golden Chickens used for host/environment discovery as part of their modular suite.
Golden Chickens reconnaissance plugin that profiles the infected host and gathers basic network information.
Reconnaissance malware used in targeted attacks to scan infected systems for the presence of specific hardware and software associated with retail and money transfer services, including Western Union software, Wacom signing pads, and Yubico YubiKeys.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.