ChonkyChicken is a Windows remote access trojan and second-stage post-exploitation implant associated with the TAG-195 malware-as-a-service ecosystem, also known as Golden Chickens or Venom Spider. It is designed to expand an initial foothold into broader enterprise compromise by combining browser credential theft, live browser session abuse, reconnaissance, lateral movement, remote execution, persistence, and surveillance in a single framework.
ChonkyChicken is typically deployed after the TinyEgg backdoor establishes initial access. Observed delivery chains tied to the broader ecosystem have used ClickFix-style social-engineering lures that trick victims into manually executing malicious commands, leading to staged OCX payload execution through legitimate Windows COM registration mechanisms. Across the TAG-195 toolset, shared traits include OCX packaging, execution through Windows registration utilities, WebSocket-based command and control, string obfuscation, filename-gating checks, and persistence through Windows Run-key mechanisms.
A defining capability of ChonkyChicken is browser-focused theft and session abuse. It can steal browser credentials and other protected browser secrets with the aid of ChromEggscalator, a modified Chrome encryption-bypass helper integrated into its workflow. It can also automate and control live Chrome or Edge sessions through Chrome DevTools Protocol, allowing operators to interact with already authenticated browser contexts and inspect logged-in sessions without necessarily triggering fresh authentication events. This makes it particularly useful for accessing business services through stolen or hijacked browser state.
ChonkyChicken also supports credential-backed and token-based remote execution for lateral movement. Its operators can use available credentials or access tokens to pivot from the initially compromised endpoint into other systems. Network discovery functions include host discovery, port scanning, share enumeration, and broader environment profiling, enabling the malware to identify reachable services and accessible internal resources. The implant is therefore suited to turning a single infected workstation into a pivot point for deeper network intrusion.
Surveillance and collection features include keylogging, clipboard capture, screenshot collection, audio recording, and monitor enumeration. Some reporting also describes a retained helper workflow for WPAD-related traffic interception. Persistence is maintained through user-level autorun mechanisms, and the malware can also remove its own persistence artifacts when directed.
A modularized successor or variant of ChonkyChicken has also been observed, using a controller-and-plugin architecture that can fetch capability modules on demand. This modular evolution likely reduces the static footprint of the base implant and supports selective capability deployment for different operators or intrusion objectives. ChonkyChicken and its related tooling are part of a financially motivated criminal malware ecosystem that has also been linked to multiple downstream threat actors using Golden Chickens services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ChonkyChicken is a more advanced implant with features like browser credential theft and live browser session control.
ChonkyChicken is a newly identified remote access trojan designed to turn one infected Windows device into a platform for credential theft, network movement, and surveillance.
ChonkyChicken, a fully featured implant that expands on TinyEgg with browser credential theft, live browser session control using Chrome DevTools Protocol (CDP), credential-backed remote execution, network reconnaissance, and sustained surveillance.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
The implant imports Windows APIs for credential use and token manipulation, and retains command strings for the creation, execution, and deletion of remote scheduled tasks.
The malware establishes connections with a C2 server using WebSockets to facilitate an interactive command shell, run operator-supplied input to the active shell session commands, send the output back to the controller, and stage OCX payloads.
These new families represent an architectural evolution, sharing common command-and-control mechanisms, persistence approaches, string obfuscation, and delivery models.
The modularized ChonkyChicken introduces a controller-and-plugin architecture, allowing for on-demand loading of 14 distinct capability modules, including process management, screen capture, keylogging, and browser theft.
ChonkyChicken is a more advanced implant with features like browser credential theft and live browser session control.
ChonkyChicken is a more advanced implant with features like browser credential theft and live browser session control.
ChonkyChicken can use available credentials or access tokens... scan ports, discover hosts, and identify accessible network shares.
ARP-based host discovery via net_arp_scan returns active hosts with their IP addresses, hostnames, and MAC addresses.
The remote_logon capability is particularly notable from a detection standpoint: it passively enumerates logged-on sessions without submitting credentials, generating no authentication events.
TCP port scanning via net_port_scan identifies active services, including SMB, RDP, WinRM, SQL Server, PostgreSQL, HTTP/S, and SSH. | The net_enumerate workflow combines ARP discovery, NetBIOS resolution, TCP scanning, and SMB enumeration into a single operation, returning IP address, MAC address, hostname, fully qualified domain name, domain name, operating system, and open ports.
The modularized ChonkyChicken introduces a controller-and-plugin architecture, allowing for on-demand loading of 14 distinct capability modules, including process management, screen capture, keylogging, and browser theft.
The net_enumerate workflow combines ARP discovery, NetBIOS resolution, TCP scanning, and SMB enumeration into a single operation, returning IP address, MAC address, hostname, fully qualified domain name, domain name, operating system, and open ports.
The 14 modules enable the following functions - ... File manipulation
The modularized ChonkyChicken introduces a controller-and-plugin architecture, allowing for on-demand loading of 14 distinct capability modules, including process management, screen capture, keylogging, and browser theft.
The modularized ChonkyChicken introduces a controller-and-plugin architecture, allowing for on-demand loading of 14 distinct capability modules, including process management, screen capture, keylogging, and browser theft.
ChonkyChicken also collects keystrokes, clipboard contents, audio recordings, and screenshots, giving attackers ongoing visibility into victim activity.
41 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An advanced implant that supports browser credential theft and live browser session control.
A second-stage implant in the TAG-195 malware-as-a-service ecosystem that performs browser credential theft, interactive session control, remote execution, reconnaissance, lateral movement, and surveillance. It can steal browser secrets, abuse active Chrome or Edge sessions via Chrome DevTools Protocol, create remote scheduled tasks, scan ports, discover hosts, identify network shares, and collect keystrokes, clipboard data, audio, and screenshots.
A fully featured implant used after initial access that adds browser credential theft, live browser session control via CDP, credential-backed remote execution, network reconnaissance, and surveillance capabilities.
A more capable TAG-195 malware family that adds browser credential theft, browser session automation, credential-backed remote execution, network reconnaissance, and surveillance.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.