Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ChonkyChicken substantially expands that capability with browser credential theft, browser session automation, credential-backed remote execution, network reconnaissance, and sustained surveillance.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The implant imports Windows APIs for credential use and token manipulation, and retains command strings for the creation, execution, and deletion of remote scheduled tasks.
Keylogging via dedicated commands records active window titles alongside captured keystrokes, providing context for interpreting captured input.
ARP-based host discovery via net_arp_scan returns active hosts with their IP addresses, hostnames, and MAC addresses.
The remote_logon capability is particularly notable from a detection standpoint: it passively enumerates logged-on sessions without submitting credentials, generating no authentication events.
The net_enumerate workflow combines ARP discovery, NetBIOS resolution, TCP scanning, and SMB enumeration into a single operation, returning IP address, MAC address, hostname, fully qualified domain name, domain name, operating system, and open ports. | TCP port scanning via net_port_scan identifies active services, including SMB, RDP, WinRM, SQL Server, PostgreSQL, HTTP/S, and SSH.
Keylogging via dedicated commands records active window titles alongside captured keystrokes, providing context for interpreting captured input.
Detects creation of the lg.txt debug log in AppData\Local\Temp, which has been observed during TAG-195's ChonkyChicken DllInstall gating and early agent execution.
Screen capture uses Graphics Device Interface APIs to transmit live frames as raw binary WebSocket data rather than JSON-formatted messages.
Clipboard monitoring collects plaintext clipboard contents through clipboard_data messages.
40 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A more capable TAG-195 malware family that adds browser credential theft, browser session automation, credential-backed remote execution, network reconnaissance, and surveillance.
A TAG-195 post-exploitation implant with operator-directed capabilities for lateral movement, credential use, network reconnaissance, surveillance, screen/audio/clipboard/keylogging collection, browser theft workflow support, WPAD helper support, and persistence via Run key execution of staged OCX payloads through regsvr32/COM-style exports.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.