ChromEggscalator is a Windows-based browser credential theft helper associated with the TAG-195 malware-as-a-service ecosystem, also known as Golden Chickens or Venom Spider. It is a modified successor to TerraStealerV2 and derives from the publicly available ChromElevator Chrome encryption-bypass tool. Rather than operating as a broad standalone implant, it appears to function as a dedicated component within TAG-195 intrusion workflows, especially alongside the ChonkyChicken malware family.
Its primary role is to bypass Chrome App-Bound Encryption protections and extract protected browser secrets from Chromium-based browsers. It has been observed integrated into ChonkyChicken’s staged browser-theft workflow, where it is executed as a helper and its output is collected and exfiltrated by the parent implant. TAG-195 modified the original tooling by removing the command-line interface, repackaging it as an OCX component, and adding execution-gating logic tied to expected filename conditions, consistent with the ecosystem’s broader emphasis on defense evasion and controlled operator deployment.
ChromEggscalator is part of a broader architectural shift in the Golden Chickens ecosystem toward modular, operator-driven tooling. Across related families, TAG-195 uses shared command-and-control patterns, persistence approaches, string obfuscation, and staged execution methods. In this context, ChromEggscalator serves as a specialized browser-theft module that complements post-exploitation activity by enabling theft of protected browser credentials and secrets from compromised Windows endpoints. Its use supports financially motivated intrusions in which operators seek access to enterprise services, authenticated browser data, and follow-on opportunities for deeper compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ChromEggscalator is a modified version of a publicly available Chrome encryption-bypass tool.
ChonkyChicken uses a tailored helper named ChromEggscalator to bypass Chrome App-Bound Encryption protections and collect protected browser secrets.
ChromEggscalator, a successor to TerraStealerV2 and a modified version of a publicly available Chrome encryption-bypass tool called ChromElevator.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modified Chrome encryption-bypass tool used within the Golden Chickens ecosystem.
A helper component used by ChonkyChicken to bypass Chrome App-Bound Encryption and steal protected browser credentials and secrets.
A modified browser credential theft utility used for Chrome credential theft, described as a successor to TerraStealerV2 and derived from the public Chrome encryption-bypass tool ChromElevator.
A TAG-195 malware family incorporating a modified Chrome encryption-bypass helper for browser credential theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.