hacker-news · Crawled Jul 24, 2026
Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
5 Actors 2 Malware
Read original article ↗
AI Summary
The Golden Chickens threat actor, tracked as TAG-195, has resurged with four new malware families: TinyEgg, ChonkyChicken, a modular variant of ChonkyChicken, and ChromEggscalator. These tools represent an evolution toward modular, operator-driven malware architectures designed for defense evasion and flexible post-compromise operations. The group uses ClickFix-style social engineering to deploy payloads, establishing persistent access and enabling browser theft, surveillance, and remote execution. The malware communicates via WebSockets to C2 servers and leverages shared infrastructure and techniques across families.
AI-extracted · verify before operational use
Extracted Entities 7 found
MITRE ATT&CK TTPs 16 techniques
T1003 OS Credential Dumping · Credential Access T1005 Data from Local System · Collection T1021 Remote Services · Lateral Movement T1040 Network Sniffing · Credential Access T1056.001 Keylogging · Collection T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1070.004 File Deletion · Defense Evasion T1071.001 Web Protocols · Command And Control T1074 Data Staged · Collection T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1110 Brute Force · Credential Access T1123 Audio Capture · Collection T1203 Exploitation for Client Execution · Execution T1566 Phishing · Initial Access