TerraCrypt is a ransomware encryption module within the Golden Chickens malware-as-a-service ecosystem, also associated with the threat actor tracked as Venom Spider. It is described as an encryption payload used for ransomware extortion and as a ransomware plugin for PureLocker, also known as CR1 Ransomware. Within the broader Golden Chickens toolchain, TerraCrypt complements other modular components used for initial access, loading, reconnaissance, credential theft, remote access, and lateral movement, enabling financially motivated intrusion sets to progress from compromise to file encryption and extortion.
Golden Chickens is a long-running criminal malware service linked to the online persona badbullzvenom and has been associated with operators and customers including FIN6, Cobalt Group, and Evilnum. Campaigns tied to this ecosystem have used employment-themed social engineering, including fake resumes and job-offer lures, to infect corporate targets. In these operations, malicious shortcut files and loader components have been used to establish execution and deploy follow-on modules, after which TerraCrypt can be introduced as the ransomware stage.
TerraCrypt has been referenced alongside other Golden Chickens modules such as VenomLNK, TerraLoader, TerraRecon, TerraStealer, TerraTV, and TerraPreter. This placement indicates its role as a late-stage payload rather than a standalone initial-access tool. Reported victimology for Golden Chickens activity includes enterprises in sectors such as financial services, e-commerce, legal services, staffing, and aerospace and defense, particularly organizations handling payment-card data or other valuable corporate information. TerraCrypt is therefore best understood as the file-encryption component of a modular cybercrime platform used in targeted financially motivated intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These modules include TerraStealer for credential harvesting, TerraTV for TeamViewer hijacking, and TerraCrypt for ransomware deployment.
Some of the other malicious tools developed by the e-crime group include ... TerraCrypt.
1 distinct technique documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
"Related Families: VenomLNK, TerraLoader, TerraStealer, TerraTV, TerraCrypt, TerraRecon, TerraWiper, lite_more_eggs, RevC2, Venom Loader"
Tool attributed to Golden Chickens (no additional functional details provided in the content).
Ransomware component within the Golden Chickens MaaS ecosystem used for ransomware deployment.
Encryption-focused plugin within the more_eggs ecosystem that supports deployment of PureLocker/CR1 ransomware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.