{"id":241529,"date":"2026-07-25T04:13:39","date_gmt":"2026-07-25T09:13:39","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/07\/golden-chickens-resurfaces-with-four-new-malware-families-and-modular-implants"},"modified":"2026-07-25T04:13:39","modified_gmt":"2026-07-25T09:13:39","slug":"golden-chickens-resurfaces-with-four-new-malware-families-and-modular-implants","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/07\/golden-chickens-resurfaces-with-four-new-malware-families-and-modular-implants","title":{"rendered":"Golden Chickens Resurfaces With Four New Malware Families and Modular Implants"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/golden-chickens-resurfaces-with-four-new-malware-families-and-modular-implants2.jpg\"><\/a><\/p>\n<p>The threat actors behind the <a href=\"https:\/\/thehackernews.com\/2025\/05\/golden-chickens-deploy-terrastealerv2.html\" target=\"_blank\">Golden Chickens<\/a> malware-as-a-service (MaaS) ecosystem have <a href=\"https:\/\/www.recordedfuture.com\/research\/tag-195-evolves-maas-ecosystem\" target=\"_blank\">resurfaced<\/a> with four new malware families, indicating that the operators are showing no signs of stopping despite <a href=\"https:\/\/thehackernews.com\/2023\/01\/experts-uncover-identity-of-mastermind.html\" target=\"_blank\">extensive public disclosures<\/a> into their inner workings.<\/p>\n<p>The malware families in question are: TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and a modified web browser credential theft utility codenamed ChromEggscalator. Recorded Future\u2019s Insikt Group is tracking the group under the moniker TAG-195.<\/p>\n<p>TAG-195 is a financially motivated malware-as-a-service (MaaS) developer whose tooling has been previously linked to TAG-127 as an operator and customer. The threat intelligence company said it has also observed TAG-127 deploying TinyEgg via <a href=\"https:\/\/www.recordedfuture.com\/research\/clickfix-campaigns-targeting-windows-and-macos\" target=\"_blank\">ClickFix-style social engineering campaigns<\/a> that trick unsuspecting users into manually executing malicious commands.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings. The malware families in question are: TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and a modified web browser credential theft [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34,20],"tags":[],"class_list":["post-241529","post","type-post","status-publish","format-standard","hentry","category-cybercrime-malcode","category-futurism"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/241529","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=241529"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/241529\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=241529"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=241529"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=241529"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}