Find notable cyber news and cases, enriched with sources, timelines, and signals.

Golden Chickens TAG-195 shifts to modular operator-driven MaaS tooling

Threat Actor Meta
First reported
Last updated
Happening score
H score 28
1 unique sources, 1 articles

Summary

Hide ▲

Golden Chickens operators, tracked as TAG-195, are refining their malware-as-a-service ecosystem with modular, operator-driven tooling, increasing defense-evasion and selective capability delivery across their malware stack. The shift expands the group’s ability to tailor payloads for initial access, credential theft, and post-exploitation control while reducing static exposure.

Related Happenings

Golden Chickens TAG-195 resurfaces with four new malware families

Malware Activity
H score30 First: 24.07.2026 13:09 Last: 24.07.2026 13:09 Sources 1

How related: The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings.

About this happening: The Golden Chickens malware ecosystem has resurfaced with four new malware families, expanding its tooling for initial access, credential theft, and modular deli...

Timeline

  1. 24.07.2026 13:09 2 articles · 9h ago

    Golden Chickens resurfaces with four new malware families and modular implants

    Initial Disclosure

    Golden Chickens, also called Venom Spider and tracked by Recorded Future as TAG-195, resurfaced with TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator, reflecting a shift toward modular, operator-driven tooling for defense evasion. Recorded Future described TinyEgg as a lightweight initial-access backdoor, ChonkyChicken as an implant that adds browser credential theft and Chrome DevTools Protocol control, and the modular variant as a controller-and-plugin design that loads 14 capability modules on demand; the same reporting also noted TAG-127 use of ClickFix-style social engineering to deploy TinyEgg through OCX payloads from attacker-controlled staging infrastructure.

    Show sources