Golden Chickens TAG-195 shifts to modular operator-driven MaaS tooling
Threat Actor Meta
Summary
Hide ▲
Show ▼
Golden Chickens operators, tracked as TAG-195, are refining their malware-as-a-service ecosystem with modular, operator-driven tooling, increasing defense-evasion and selective capability delivery across their malware stack. The shift expands the group’s ability to tailor payloads for initial access, credential theft, and post-exploitation control while reducing static exposure.
Related Happenings
Golden Chickens TAG-195 resurfaces with four new malware families
Malware Activity
H score30
First: 24.07.2026 13:09
Last: 24.07.2026 13:09
Sources 1
How related:
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings.
About this happening:
The Golden Chickens malware ecosystem has resurfaced with four new malware families, expanding its tooling for initial access, credential theft, and modular deli...
Golden Chickens TAG-195 resurfaces with four new malware families
Malware ActivityHow related: The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings.
About this happening: The Golden Chickens malware ecosystem has resurfaced with four new malware families, expanding its tooling for initial access, credential theft, and modular deli...
Timeline
-
24.07.2026 13:09 2 articles · 9h ago
Golden Chickens resurfaces with four new malware families and modular implants
Initial DisclosureGolden Chickens, also called Venom Spider and tracked by Recorded Future as TAG-195, resurfaced with TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator, reflecting a shift toward modular, operator-driven tooling for defense evasion. Recorded Future described TinyEgg as a lightweight initial-access backdoor, ChonkyChicken as an implant that adds browser credential theft and Chrome DevTools Protocol control, and the modular variant as a controller-and-plugin design that loads 14 capability modules on demand; the same reporting also noted TAG-127 use of ClickFix-style social engineering to deploy TinyEgg through OCX payloads from attacker-controlled staging infrastructure.
Show sources
- Golden Chickens Resurfaces With Four New Malware Families and Modular Implants — thehackernews.com — 24.07.2026 13:09
- Golden Chickens Resurfaces With Four New Malware Families and Modular Implants — thehackernews.com — 24.07.2026 13:09