Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ChonkyChicken Malware Targets Chrome Credentials

ChonkyChicken Malware Targets Chrome Credentials

Posted on July 24, 2026 By CWS

ChonkyChicken, a newly discovered remote access trojan, has emerged as a significant threat to Windows devices, enabling credential theft, lateral movement, and surveillance. The malware is part of the TAG-195 ecosystem, also known as Golden Chickens or Venom Spider, which offers tools to financially motivated cybercriminals.

Initial Entry and Delivery Mechanism

Recent attacks leveraging ChonkyChicken begin with ClickFix lures, which are deceptive verification pages that trick users into executing commands in the Windows Run dialog. This method downloads an OCX payload, which is then launched using regsvr32.exe, allowing the initial TinyEgg backdoor to establish access before deploying ChonkyChicken.

Security researchers at Recorded Future’s Insikt Group discovered this malware while monitoring the evolution of the TAG-195 ecosystem. The group identified ChonkyChicken as a second-stage implant capable of browser credential theft, remote session control, execution, reconnaissance, and persistent monitoring.

Broader Implications and Threats

ChonkyChicken’s impact is extensive, going beyond password theft. The malware enables attackers to exploit browser data and active sessions to infiltrate business services, map internal networks, and compromise additional devices. This highlights the critical need for organizations to prioritize the monitoring of browser-stored credentials and not dismiss saved passwords as a low-risk convenience.

To bypass security measures like Chrome App-Bound Encryption, ChonkyChicken uses a specialized tool called ChromEggscalator to collect sensitive browser data. The harvested information is then transmitted back to the attacker, who can control live browser sessions through Chrome DevTools Protocol automation, maintaining access even if passwords are changed.

Network Movement and Defense Strategies

ChonkyChicken is adept at lateral movement, exploiting credentials or access tokens, checking logged-in sessions without triggering authentication events, and performing network reconnaissance. It can create remote tasks, scan ports, discover hosts, and identify network shares, positioning itself as more than just a basic password stealer.

To combat this threat, security teams should monitor for regsvr32 abuse, especially involving files in user-writable locations like TEMP or AppData, and restrict the execution of pasted commands where feasible. Additional measures include blocking regsvr32.exe from loading OCX files from user-writable folders and investigating any Chrome or Edge processes initiated with remote-debugging options.

Modular Capabilities and Recommendations

ChonkyChicken also features modular spying capabilities, collecting keystrokes, clipboard contents, audio, and screenshots to maintain visibility into victim activities. A modular version can request additional capability plugins as needed, minimizing the initial malicious code footprint.

All current TAG-195 malware families employ tactics to evade detection, such as filename checks to avoid execution in unwanted environments, persistence through Windows Run keys, and obscured strings. Security teams are advised to enforce phishing-resistant multifactor authentication and limit administrator privileges across workstations.

Indicators of compromise (IoCs) include specific IP addresses, domains, and file names associated with the malware’s operation. Organizations should use controlled threat intelligence platforms to investigate these IoCs and assess their own exposure to similar threats.

Cyber Security News Tags:browser security, ChonkyChicken, Chrome security, credential theft, cyber threats, Cybersecurity, Golden Chickens, Malware, network security, remote access trojan, security measures, TAG-195, Venom Spider, Windows security

Post navigation

Previous Post: Certighost Vulnerability Allows Domain Controller Impersonation
Next Post: BlueNoroff Targets Crypto Wallets via Phishing on Zoom

Related Posts

NAKIVO v11.2 Enhances Replication and vSphere Support NAKIVO v11.2 Enhances Replication and vSphere Support Cyber Security News
Windows Snipping Tool Flaw Exposes User Credentials Windows Snipping Tool Flaw Exposes User Credentials Cyber Security News
New Streamlit Vulnerability Allows Hackers to Launch Cloud Account Takeover Attacks New Streamlit Vulnerability Allows Hackers to Launch Cloud Account Takeover Attacks Cyber Security News
AsyncRAT Uses Fileless Loader to Bypass Detections and Gain Remote Access AsyncRAT Uses Fileless Loader to Bypass Detections and Gain Remote Access Cyber Security News
Matanbuchus Malware Downloader Evading AV Detections by Changing Components Matanbuchus Malware Downloader Evading AV Detections by Changing Components Cyber Security News
Critical ScreenConnect Vulnerability Let Attackers Expose Sensitive Configuration Data Critical ScreenConnect Vulnerability Let Attackers Expose Sensitive Configuration Data Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cl0p Hackers Target Windchill Servers for Data Theft
  • BlueNoroff Targets Crypto Wallets via Phishing on Zoom
  • ChonkyChicken Malware Targets Chrome Credentials
  • Certighost Vulnerability Allows Domain Controller Impersonation
  • Malicious Bing Ads Exploit AI Interests to Spread Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cl0p Hackers Target Windchill Servers for Data Theft
  • BlueNoroff Targets Crypto Wallets via Phishing on Zoom
  • ChonkyChicken Malware Targets Chrome Credentials
  • Certighost Vulnerability Allows Domain Controller Impersonation
  • Malicious Bing Ads Exploit AI Interests to Spread Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark