logo

ChonkyChicken Malware Steals Chrome Credentials, Moves Laterally and Spies on Victims

ID: b4125b43-d739-5fb8-870b-6a65b80a987b

STIX ID: report--b4125b43-d739-5fb8-870b-6a65b80a987b

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-07-24

Date Updated: 2026-07-25

Author: Tushar Subhra Dutta

...
...

ChonkyChicken is a newly identified modular remote-access trojan associated with the TAG-195 (Golden Chickens/Venom Spider) malware-as-a-service ecosystem that steals protected browser credentials (via a helper called ChromEggscalator), abuses Chrome DevTools Protocol to hijack active sessions, captures keystrokes/clipboard/audio/screenshots, and supports lateral movement and persistence (regsvr32 loading of OCX files). The report details the ClickFix lure delivery chain, IoCs (IPs, domains, filenames, registry Run key), recommended detections and mitigations (block regsvr32 abuse, monitor remote-debugging WebSocket activity, enforce phishing-resistant MFA, limit admin privileges), and notes active use by financially motivated operators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.