Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-25 ยท updated: 2026-07-25 ยท tags: [incident, cybercrime-group, loader, rat] ยท confidence: high ยท affected_sectors: [technology] ยท au_impact: false

Golden Chickens Resurfaces With Four New Malware Families

The Golden Chickens MaaS ecosystem operators (TAG-195) resurfaced with four new malware families: TinyEgg, ChonkyChicken, a modularised variant, and a credential theft utility called ChromEggscalator. TAG-127 observed deploying TinyEgg via ClickFix-style social engineering.

Overview

Attribute Detail
Date 2026-07-24
Threat Actor TAG-195 (Golden Chickens MaaS ecosystem)
Associated Actor TAG-127 (TinyEgg deployer)
New Malware TinyEgg, ChonkyChicken, modular variant, ChromEggscalator

New Malware Families

Malware Type Description
TinyEgg Loader Deployed via ClickFix-style social engineering by TAG-127
ChonkyChicken Payload Modular malware with multiple capabilities
Modular variant Framework Extensible malware framework
ChromEggscalator Utility Credential theft tool targeting Chromium-based browsers

Significance

The resurgence of the Golden Chickens ecosystem with a diversified malware portfolio indicates an active and evolving MaaS operation. The addition of ClickFix-style social engineering for initial access aligns with broader industry trends in malware delivery.

Related Pages