TinyEgg is a lightweight Windows backdoor associated with the Golden Chickens malware-as-a-service ecosystem, also tracked as Venom Spider or TAG-195. It is designed primarily for initial access, host profiling, and establishment of a foothold before handing off broader post-exploitation activity to later-stage tooling such as ChonkyChicken. Observed functionality includes interactive shell access, command execution, host profiling, command-and-control communications over WebSockets using a task-driven protocol, and persistence management. TinyEgg has also been reported to terminate execution in sandbox or automated analysis environments, indicating built-in defense-evasion logic. Across the TAG-195 toolset, TinyEgg shares architectural traits including OCX packaging, execution through legitimate Windows COM registration mechanisms, string obfuscation, filename-based execution gating, and a consistent persistence model using user-level autorun mechanisms. Delivery has been observed through ClickFix-style social-engineering lures in which victims are tricked into manually executing malicious commands that invoke a legitimate Windows utility to load the staged payload. TinyEgg has been linked to operations involving TAG-127 as a customer or operator within the broader Golden Chickens ecosystem, which has also been associated with financially motivated cybercrime activity affecting enterprise environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TinyEgg serves as a lightweight backdoor for initial access and host profiling, passing post-exploitation capabilities to ChonkyChicken.
That action downloads an OCX payload and launches it with regsvr32.exe, allowing the first-stage TinyEgg backdoor to establish access before ChonkyChicken is delivered.
TinyEgg, a lightweight initial-access backdoor providing host profiling, interactive shell access, and persistence management.
TinyEgg, a lightweight initial-access backdoor providing host profiling, interactive shell access, and persistence management.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware establishes connections with a C2 server using WebSockets to facilitate an interactive command shell, run operator-supplied input to the active shell session commands, send the output back to the controller, and stage OCX payloads.
ClickFix-style social engineering campaigns that trick unsuspecting users into manually executing malicious commands. | The threat intelligence company said it has also observed TAG-127 deploying TinyEgg via ClickFix-style social engineering campaigns that trick unsuspecting users into manually executing malicious commands.
These new families represent an architectural evolution, sharing common command-and-control mechanisms, persistence approaches, string obfuscation, and delivery models.
TinyEgg serves as a lightweight backdoor for initial access and host profiling, passing post-exploitation capabilities to ChonkyChicken.
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A lightweight backdoor used for initial access and host profiling, then handing off post-exploitation capabilities to ChonkyChicken.
A first-stage backdoor used to establish initial access before delivery of ChonkyChicken.
A lightweight initial-access backdoor used for host profiling, interactive shell access, persistence management, and staging follow-on payloads. It is delivered via ClickFix-style social engineering and is designed to terminate if sandbox or automated analysis environments are detected.
A lightweight initial-access backdoor used in TAG-195 campaigns that profiles hosts, provides interactive shell access, and manages persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.