TerraPreter is a Golden Chickens malware-as-a-service component used as an in-memory Meterpreter shell on Windows systems. It is associated with financially motivated intrusion activity and has been observed in operations linked to groups including Evilnum, as well as in broader Golden Chickens campaigns historically used by actors such as FIN6 and Cobalt Group. TerraPreter functions as a post-compromise access tool that gives operators interactive control for hands-on-keyboard activity, including discovery, credential theft, and lateral movement.
TerraPreter is typically not the initial infection vector itself, but a later-stage payload delivered through the Golden Chickens infection chain. Observed delivery chains include spearphishing and fake job or resume lures that lead to execution of VenomLNK and TerraLoader, after which TerraPreter is fetched and launched while abusing legitimate Windows utilities for stealth. In documented cases, TerraPreter was loaded as an ActiveX control and then used to beacon to command-and-control infrastructure through a rogue copy of a legitimate utility.
Its core role is to provide a Meterpreter session in memory, enabling manual operator actions rather than broad autonomous functionality. This makes it useful for targeted intrusions where attackers want flexible post-exploitation access, internal reconnaissance, credential collection, and pivoting within victim environments. TerraPreter has been discussed alongside other Golden Chickens modules such as TerraStealer, TerraTV, TerraLoader, and More_eggs, reflecting its place in a modular ecosystem used in selective enterprise-focused campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Among the tools used by the Evilnum group are More_eggs, TerraPreter, TerraStealer, and TerraTV.
TerraLoader then installs msxsl in the user’s roaming profile and loads the payload, TerraPreter, an ActiveX control (.ocx file) downloaded from Amazon Web Services. At this point, TerraPreter begins beaconing to a Command & Control server (C2) via the rogue copy of msxsl.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named malware/tool in the Golden Chickens ecosystem that the content states was used by Evilnum.
A malware tool associated with Golden Chickens and used by Evilnum in some cases.
A more_eggs module that provides an in-memory Meterpreter shell for post-compromise access and control.
Golden Chickens plugin that provides a Meterpreter-style shell for hands-on-keyboard activity including discovery, lateral movement, and credential theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.