type: incident ยท created: 2026-07-25 ยท updated: 2026-07-25 ยท tags: [incident, cybercrime-group, loader, rat] ยท confidence: high ยท affected_sectors: [technology] ยท au_impact: false
Golden Chickens Resurfaces With Four New Malware Families
The Golden Chickens MaaS ecosystem operators (TAG-195) resurfaced with four new malware families: TinyEgg, ChonkyChicken, a modularised variant, and a credential theft utility called ChromEggscalator. TAG-127 observed deploying TinyEgg via ClickFix-style social engineering.
Overview
| Attribute | Detail |
|---|---|
| Date | 2026-07-24 |
| Threat Actor | TAG-195 (Golden Chickens MaaS ecosystem) |
| Associated Actor | TAG-127 (TinyEgg deployer) |
| New Malware | TinyEgg, ChonkyChicken, modular variant, ChromEggscalator |
New Malware Families
| Malware | Type | Description |
|---|---|---|
| TinyEgg | Loader | Deployed via ClickFix-style social engineering by TAG-127 |
| ChonkyChicken | Payload | Modular malware with multiple capabilities |
| Modular variant | Framework | Extensible malware framework |
| ChromEggscalator | Utility | Credential theft tool targeting Chromium-based browsers |
Significance
The resurgence of the Golden Chickens ecosystem with a diversified malware portfolio indicates an active and evolving MaaS operation. The addition of ClickFix-style social engineering for initial access aligns with broader industry trends in malware delivery.
Related Pages
- Bluenoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery โ North Korean targeting of crypto wallets via phishing