The cybercriminal group known as Golden Chickens, also referred to as Venom Spider, has introduced four new malware families, signaling a significant evolution in their malware-as-a-service (MaaS) offerings. This development underscores the group’s ongoing commitment to refining their malicious toolkit despite previous public disclosures about their activities.
Introduction of New Malware Families
The newly identified malware families are:
- TinyEgg: A lightweight backdoor designed for initial access, providing capabilities such as host profiling, interactive shell access, and persistence management.
- ChonkyChicken: An advanced implant that builds upon TinyEgg’s functionalities, adding features like browser credential theft, live browser session control via the Chrome DevTools Protocol (CDP), credential-backed remote execution, network reconnaissance, and continuous surveillance.
- Modular ChonkyChicken: A variant of ChonkyChicken that employs a controller-and-plugin architecture, enabling the dynamic loading of 14 distinct capability modules as needed, rather than embedding all functionalities within a single implant.
- ChromEggscalator: An updated version of the earlier TerraStealerV2, this tool is a modified iteration of the publicly available Chrome encryption-bypass utility known as ChromElevator.
Strategic Shift to Modular Architecture
This transition to a modular framework indicates Golden Chickens’ strategic move towards more adaptable and evasive malware designs. By adopting a modular approach, the group can selectively deploy specific functionalities, enhancing their ability to evade detection and tailor attacks to particular targets.
Delivery Mechanisms and Operational Tactics
Golden Chickens’ malware is typically disseminated through social engineering tactics, notably ClickFix-style campaigns. These campaigns deceive users into executing malicious commands, leading to the installation of TinyEgg. Once established, TinyEgg serves as a conduit for deploying more sophisticated tools like ChonkyChicken. Notably, TinyEgg is programmed to terminate its operations if it detects sandbox or automated analysis environments, thereby complicating efforts to analyze and mitigate the threat.
Collaborations and Broader Implications
The group’s tools have been utilized by various cybercriminal entities, including Cobalt Group (also known as Cobalt Gang), Evilnum, and FIN6. Additionally, another threat actor, identified as TAG-127, has been associated with the Golden Chickens MaaS, employing delivery methods such as ClickFix or VenomLNK.
The introduction of these new malware families by Golden Chickens highlights the persistent and evolving nature of cyber threats. Their shift towards modular, operator-driven tools not only enhances their operational flexibility but also poses significant challenges for cybersecurity defenses. Organizations must remain vigilant, continuously updating their security protocols and educating personnel to recognize and respond to such sophisticated threats.