TAG-195, also known as Golden Chickens or Venom Spider, is a financially motivated MaaS developer long linked to credential theft and remote access tooling for multiple criminal operators.
Insikt Group recently identified four new malware families in this ecosystem, naming two of them TinyEgg and ChonkyChicken, alongside a modularized ChonkyChicken variant and a Chrome-focused helper dubbed ChromEggscalator.
TinyEgg serves as a lightweight initial-access backdoor that lays the groundwork for follow-on activity once a target is compromised.
It focuses on core functionality, host profiling to inventory the victim environment, interactive shell access for hands-on keyboard control, and management of persistence mechanisms to ensure it survives reboots and remains available to operators
Golden Chickens Unleashes TinyEgg
Insikt Group has observed TAG-127, a threat group consuming TAG-195’s MaaS offerings, deploying TinyEgg via “ClickFix”-style campaigns that weaponize fake security verification pages.
In these scenarios, victims are tricked into manually executing malicious commands that leverage legitimate Windows utilities to download and install TinyEgg payloads from user‑writable directories, helping the malware blend in with normal system activity.

This delivery model reduces reliance on exploit chains and instead abuses user trust and living‑off‑the‑land binaries for execution.
ChonkyChicken represents a much more capable second stage, substantially expanding what operators can do post-compromise compared to TinyEgg.
Beyond backdoor access, ChonkyChicken integrates browser credential theft, browser session automation, credential-backed remote execution, network reconnaissance, and sustained surveillance features to support long-term, interactive operations inside victim environments.
Both TinyEgg and ChonkyChicken replace opportunistic exfiltration with a structured, bidirectional WebSocket tasking framework, enabling continuous, operator-directed command-and-control (C2) rather than one-off data theft.
![ClickFix web page, screenly[.]cam, leveraged by TAG-127 to distribute malware (Source: Recorded Future)](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqZWVVgzyH5Pwm50ZTkRfNugpy913SqiGqBEebn_RdbsAM5Xh__BNhfWnDVFWURPy0C6rWO7LFRGhSP_B6kg6F-Y3sGSQEOPMYVpTeo3avSW05nVC5TeLthZoAV5Jf0Cd57DqsUUMp4aQlDESmEkhFhtvYQfT-722fXivDbLGTlmZAYJoB-nIgMS3aA_EN/s1186/media_131aa8b67eed88cb74e72faef34c978bf3f0cc190-1.webp)
A modularized variant of ChonkyChicken pushes this further by adopting a controller-and-plugin architecture where a lean base implant dynamically requests and loads discrete capability modules from attacker-controlled infrastructure.
Insikt Group notes this design supports at least fourteen modules and almost certainly reduces the static detection footprint of the base implant by avoiding a monolithic feature set baked into a single binary.
It also allows operators to deploy only the capabilities required for each intrusion, limiting exposure if specific customers or campaigns are compromised and aligning neatly with MaaS commercial incentives, recordedfuture said.
Indicators of Compromise
| Category | Indicator / Pattern | Associated Family | Notes for Detection |
|---|---|---|---|
| Initial access | “ClickFix”-style fake security verification pages prompting users to run copied commands | TinyEgg (delivery), TAG-127 ops | Look for users pasting and running suspicious clipboard commands in terminals or PowerShell |
| Living-off-the-land | Use of legitimate Windows system utilities to download and execute payloads from user-writable dirs | TinyEgg, ChonkyChicken | Monitor LOLBIN abuse (e.g., curl, certutil, mshta-style behavior) from temp/user paths |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.