Executive Summary
Insikt Group has identified four new malware families within the TAG-195 (Golden Chickens/Venom Spider) Malware-as-a-Service (MaaS) ecosystem: TinyEgg, ChonkyChicken, a modular ChonkyChicken variant, and ChromEggscalator. This transition reflects a strategic architectural shift toward modular, operator-driven tooling designed to reduce static detection footprints while enabling selective capability deployment. TAG-127, a known customer, has been observed deploying these tools via 'ClickFix' social engineering campaigns.
The technical evolution resolves previous capability gaps, specifically addressing Chrome App-Bound Encryption (ABE) bypass and introducing robust Command and Control (C2) via WebSockets. ChonkyChicken represents a significant threat, offering browser session automation via the Chrome DevTools Protocol (CDP), lateral movement via credential-backed execution, and extensive network reconnaissance. This maturity in tradecraft suggests TAG-195 is positioning itself to serve high-end criminal operators with specialized operational requirements.
The modular design allows attackers to load only the necessary plugins on demand, complicating forensic analysis and initial detection. Affected sectors likely include financial services and retail, consistent with TAG-195's history with groups like FIN6 and Cobalt Group. Defenders should prioritize detecting ClickFix delivery mechanisms, suspicious registry Run keys, and unusual browser processes initiated with remote debugging flags.
Key Details
Threat Name
TAG-195 MaaS Ecosystem
Affects
—
Adversary
TAG-195 Other Adversaries and Aliases: TAG-127; FIN6; Cobalt Group; Evilnum
MITRE Techniques
Malware/Tools
TinyEgg, ChonkyChicken, ChromEggscalator, Modular ChonkyChicken, TerraStealerV2, TerraLogger, More_eggs, MarkiRAT, VenomLNK, RevC2
