Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings.
Intelligence analysis by Llama

The four new families indicate an architectural transition and evolution in the TAG-195 MaaS ecosystem, with all four families sharing a common set of architectural traits, including consistent command-and-control mechanisms, a shared persistence approach, string obfuscation, and execution via the same delivery model.
Imagine a group of hackers who create and sell malware to other hackers. They've just released four new types of malware that can steal information from computers and control the browser. This is a big deal because it shows that these hackers are still active and getting better at what they do.
Analysis
A $60B Vote of Confidence
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings. The four new families are TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and a modified web browser credential theft utility codenamed ChromEggscalator. Recorded Future's Insikt Group is tracking the group under the moniker TAG-195.
Why Cursor?
The malware families in question are designed to provide initial access and profiling functions, with all post-exploitation capability passed on to ChonkyChicken. TinyEgg is also designed to terminate execution if sandbox and automated analysis environments are detected. The malware establishes connections with a C2 server using WebSockets to facilitate an interactive command shell, run operator-supplied input to the active shell session commands, send the output back to the controller, and stage OCX payloads.
The Road Ahead
The shift is a sign that Golden Chickens, also called Venom Spider, is actively refining its arsenal through active development, while deliberately moving to modular, operator-driven tooling for defense evasion. Associated with a malware family called More_eggs, the threat actor's tools have been put to use by other cybercrime groups like Cobalt Group (aka Cobalt Gang), Evilnum, and FIN6. Another threat actor associated with the Golden Chickens MaaS is TAG-127, which uses ClickFix or VenomLNK as delivery methods.
Key points
- Golden Chickens malware-as-a-service (MaaS) ecosystem has resurfaced with four new malware families.
- The four new families are TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and a modified web browser credential theft utility codenamed ChromEggscalator.
- Recorded Future's Insikt Group is tracking the group under the moniker TAG-195.
- The malware families are designed to provide initial access and profiling functions, with all post-exploitation capability passed on to ChonkyChicken.
The development of modular malware families like Golden Chickens may lead to more targeted and effective cybersecurity measures, as defenders can better understand and prepare for the evolving threat landscape.
The resurfacing of Golden Chickens with new malware families and modular implants may indicate a more sophisticated and adaptable threat actor, potentially leading to increased sophistication and evasion capabilities in future attacks.



