Golden Chickens TAG-195 Launches TinyEgg and ChonkyChicken Modular Malware

TAG-195, also known as Golden Chickens or Venom Spider, is a financially motivated MaaS developer long linked to credential theft and remote access tooling for multiple criminal operators.

Insikt Group recently identified four new malware families in this ecosystem, naming two of them TinyEgg and ChonkyChicken, alongside a modularized ChonkyChicken variant and a Chrome-focused helper dubbed ChromEggscalator.

TinyEgg serves as a lightweight initial-access backdoor that lays the groundwork for follow-on activity once a target is compromised.

It focuses on core functionality, host profiling to inventory the victim environment, interactive shell access for hands-on keyboard control, and management of persistence mechanisms to ensure it survives reboots and remains available to operators

Golden Chickens Unleashes TinyEgg

Insikt Group has observed TAG-127, a threat group consuming TAG-195’s MaaS offerings, deploying TinyEgg via “ClickFix”-style campaigns that weaponize fake security verification pages.

In these scenarios, victims are tricked into manually executing malicious commands that leverage legitimate Windows utilities to download and install TinyEgg payloads from user‑writable directories, helping the malware blend in with normal system activity.

Summary of new TAG-195 malware (Source: Recorded Future)
Summary of new TAG-195 malware (Source: Recorded Future)

This delivery model reduces reliance on exploit chains and instead abuses user trust and living‑off‑the‑land binaries for execution.

ChonkyChicken represents a much more capable second stage, substantially expanding what operators can do post-compromise compared to TinyEgg.

Beyond backdoor access, ChonkyChicken integrates browser credential theft, browser session automation, credential-backed remote execution, network reconnaissance, and sustained surveillance features to support long-term, interactive operations inside victim environments.

Both TinyEgg and ChonkyChicken replace opportunistic exfiltration with a structured, bidirectional WebSocket tasking framework, enabling continuous, operator-directed command-and-control (C2) rather than one-off data theft.

ClickFix web page, screenly[.]cam, leveraged by TAG-127 to distribute malware (Source: Recorded Future)
ClickFix web page, screenly[.]cam, leveraged by TAG-127 to distribute malware (Source: Recorded Future)

A modularized variant of ChonkyChicken pushes this further by adopting a controller-and-plugin architecture where a lean base implant dynamically requests and loads discrete capability modules from attacker-controlled infrastructure.

Insikt Group notes this design supports at least fourteen modules and almost certainly reduces the static detection footprint of the base implant by avoiding a monolithic feature set baked into a single binary.

It also allows operators to deploy only the capabilities required for each intrusion, limiting exposure if specific customers or campaigns are compromised and aligning neatly with MaaS commercial incentives, recordedfuture said.

Indicators of Compromise

CategoryIndicator / PatternAssociated FamilyNotes for Detection
Initial access“ClickFix”-style fake security verification pages prompting users to run copied commands TinyEgg (delivery), TAG-127 opsLook for users pasting and running suspicious clipboard commands in terminals or PowerShell
Living-off-the-landUse of legitimate Windows system utilities to download and execute payloads from user-writable dirsTinyEgg, ChonkyChickenMonitor LOLBIN abuse (e.g., curl, certutil, mshta-style behavior) from temp/user paths

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. 

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories