Recordedfuture Golden Chickens Unveils Four New Modular Malware Families Targeting Chrome Credentials
Article Content
- •TAG-195 has launched four new malware families aimed at credential theft and browser hijacking.
- •The malware employs ClickFix-style lures to trick users into executing malicious commands.
- •Defenders are advised to focus on detecting specific execution patterns and unusual network communications.
TAG-195, also known as Golden Chickens or Venom Spider, has launched four new malware families: TinyEgg, ChonkyChicken, a modular variant of ChonkyChicken, and ChromEggscalator. These families are designed to enhance credential theft and browser session hijacking capabilities. The malware utilizes ClickFix-style lures to trick victims into executing malicious commands. TinyEgg serves as a lightweight backdoor, while ChonkyChicken expands functionality to include browser credential theft and network reconnaissance. The modular architecture allows for selective provisioning of capabilities, reducing detection risks. Insikt Group has linked TAG-195 to previous operations and warns defenders to prioritize detection of specific execution chains and unusual communications. The malware primarily targets Windows systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Golden Chickens and ClickFix in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Rapid7 Reports Surge in Vulnerability Exploitation Outpacing Patching Efforts Rapid7's Q2 2026 Threat Landscape Report reveals a significant increase in vulnerability disclosures, with high and critical vulnerabilities doubling to 8,539. Newly exploited vulnerabilities surged by 40%, with 62% requiring no user interaction to exploit. The report highlights that attackers are leveraging…
Healthcare Cyberattacks Disrupt Patient Care and Expose Sensitive Data Two major healthcare companies, Boston Scientific and Nutex Health, reported cyberattacks that compromised patient data and disrupted operations. Boston Scientific's systems were breached on August 25, affecting the functionality of pacemakers and other heart devices, preventing remote monitoring. The company is…