Golden Chickens Launches Four Modular Malware Families to Steal Chrome Credentials and Hijack Browser Sessions
ID: 57adbcf7-d92a-5f7d-a0b4-5568b0263321
STIX ID: report--57adbcf7-d92a-5f7d-a0b4-5568b0263321
Feed Name: GBHackers
Insikt Group reports that TAG-195 (Golden Chickens/Venom Spider) has developed a modular MaaS ecosystem—TinyEgg, ChonkyChicken (and a modular variant), and ChromEggscalator—that enables lightweight initial access, robust post-exploitation (browser credential theft and real-time session hijacking via Chrome DevTools Protocol), and a Chrome ABE bypass; campaigns using ClickFix-style social engineering and OCX/ regsvr32 execution have been observed, with associated IOCs including multiple lure domains, C2/staging hosts, and an identified hosting IP.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
