Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ChonkyChicken Malware Targets Chrome Credentials

ChonkyChicken Malware Targets Chrome Credentials

Posted on July 24, 2026 By CWS

ChonkyChicken, a newly discovered remote access trojan, has emerged as a significant threat to Windows devices, enabling credential theft, lateral movement, and surveillance. The malware is part of the TAG-195 ecosystem, also known as Golden Chickens or Venom Spider, which offers tools to financially motivated cybercriminals.

Initial Entry and Delivery Mechanism

Recent attacks leveraging ChonkyChicken begin with ClickFix lures, which are deceptive verification pages that trick users into executing commands in the Windows Run dialog. This method downloads an OCX payload, which is then launched using regsvr32.exe, allowing the initial TinyEgg backdoor to establish access before deploying ChonkyChicken.

Security researchers at Recorded Future’s Insikt Group discovered this malware while monitoring the evolution of the TAG-195 ecosystem. The group identified ChonkyChicken as a second-stage implant capable of browser credential theft, remote session control, execution, reconnaissance, and persistent monitoring.

Broader Implications and Threats

ChonkyChicken’s impact is extensive, going beyond password theft. The malware enables attackers to exploit browser data and active sessions to infiltrate business services, map internal networks, and compromise additional devices. This highlights the critical need for organizations to prioritize the monitoring of browser-stored credentials and not dismiss saved passwords as a low-risk convenience.

To bypass security measures like Chrome App-Bound Encryption, ChonkyChicken uses a specialized tool called ChromEggscalator to collect sensitive browser data. The harvested information is then transmitted back to the attacker, who can control live browser sessions through Chrome DevTools Protocol automation, maintaining access even if passwords are changed.

Network Movement and Defense Strategies

ChonkyChicken is adept at lateral movement, exploiting credentials or access tokens, checking logged-in sessions without triggering authentication events, and performing network reconnaissance. It can create remote tasks, scan ports, discover hosts, and identify network shares, positioning itself as more than just a basic password stealer.

To combat this threat, security teams should monitor for regsvr32 abuse, especially involving files in user-writable locations like TEMP or AppData, and restrict the execution of pasted commands where feasible. Additional measures include blocking regsvr32.exe from loading OCX files from user-writable folders and investigating any Chrome or Edge processes initiated with remote-debugging options.

Modular Capabilities and Recommendations

ChonkyChicken also features modular spying capabilities, collecting keystrokes, clipboard contents, audio, and screenshots to maintain visibility into victim activities. A modular version can request additional capability plugins as needed, minimizing the initial malicious code footprint.

All current TAG-195 malware families employ tactics to evade detection, such as filename checks to avoid execution in unwanted environments, persistence through Windows Run keys, and obscured strings. Security teams are advised to enforce phishing-resistant multifactor authentication and limit administrator privileges across workstations.

Indicators of compromise (IoCs) include specific IP addresses, domains, and file names associated with the malware’s operation. Organizations should use controlled threat intelligence platforms to investigate these IoCs and assess their own exposure to similar threats.

Cyber Security News Tags:browser security, ChonkyChicken, Chrome security, credential theft, cyber threats, Cybersecurity, Golden Chickens, Malware, network security, remote access trojan, security measures, TAG-195, Venom Spider, Windows security

Post navigation

Previous Post: Certighost Vulnerability Allows Domain Controller Impersonation
Next Post: BlueNoroff Targets Crypto Wallets via Phishing on Zoom

Related Posts

SILENTCONNECT Malware Threatens Windows Security SILENTCONNECT Malware Threatens Windows Security Cyber Security News
APT36 Attacking BOSS Linux Systems With Weaponized ZIP Files to Steal Sensitive Data APT36 Attacking BOSS Linux Systems With Weaponized ZIP Files to Steal Sensitive Data Cyber Security News
Threat Actors are Hiring Insiders in Banks, Telecoms, and Tech from ,000 to ,000 for Access or Data Threat Actors are Hiring Insiders in Banks, Telecoms, and Tech from $3,000 to $15,000 for Access or Data Cyber Security News
New Zip Slip Vulnerability Allows Attackers to Manipulate ZIP Files During Decompression New Zip Slip Vulnerability Allows Attackers to Manipulate ZIP Files During Decompression Cyber Security News
OpenMatter Network Enhances Platform for Secure AI Collaboration OpenMatter Network Enhances Platform for Secure AI Collaboration Cyber Security News
New QUIC-LEAK Vulnerability Let Attackers Exhaust Server Memory and Trigger DoS Attack New QUIC-LEAK Vulnerability Let Attackers Exhaust Server Memory and Trigger DoS Attack Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027
  • Sensitive Employee Data Breach at Natural Resources Wales
  • Hackers Exploit Google Services for Phishing Scams

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027
  • Sensitive Employee Data Breach at Natural Resources Wales
  • Hackers Exploit Google Services for Phishing Scams

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark