The cybercriminal group known as Golden Chickens has launched four new malware families, demonstrating an ongoing evolution in their malware-as-a-service (MaaS) operations. These developments highlight a continued threat posed by the group, despite previous exposés of their activities.
Emerging Malware Families
The newly identified malware families are TinyEgg, ChonkyChicken, its modular variant, and ChromEggscalator, a tool for stealing browser credentials. The group, tracked by Recorded Future’s Insikt Group under the name TAG-195, is known for its financial motivations and sophisticated MaaS offerings.
TAG-195 has been linked to another group, TAG-127, which has utilized TinyEgg in social engineering schemes. These campaigns deceive users into executing harmful commands, showcasing the group’s adept use of manipulation to spread their malware.
Architectural Advancements
According to Recorded Future, the introduction of these families marks a strategic shift in TAG-195’s operations. The new malware shares common traits such as command-and-control methods, persistence strategies, and delivery models, indicating a concerted effort to refine their toolkit.
TinyEgg serves as a lightweight backdoor for initial system access and management, while ChonkyChicken expands on these capabilities by adding browser credential theft and remote execution features. The modular version of ChonkyChicken introduces a flexible architecture, allowing specific functionalities to be loaded as needed.
Modular Malware Implications
The modular approach adopted by Golden Chickens suggests a tactical move towards more adaptable and evasive malware. The 14 modules available in the modular ChonkyChicken allow for diverse operations, ranging from process management to network reconnaissance, and even keylogging and audio capture.
This design not only reduces the likelihood of detection but also aligns with the commercial aspects of the MaaS model. By offering scalable capabilities, Golden Chickens can meet varied operational needs while minimizing exposure if a customer is compromised.
The cybersecurity community remains vigilant as Golden Chickens continues to refine their approach, with potential implications for a wide range of industries and individuals. The ongoing development of their toolkit suggests that the group is committed to maintaining a competitive edge in the realm of cybercrime.
