logo

TerraStealerV2 and TerraLogger: Golden Chickens' New Malware Families Discovered

ID: 58f71e33-2066-5e54-80a2-97cf21b41d06

STIX ID: report--58f71e33-2066-5e54-80a2-97cf21b41d06

Feed Name: Recorded Future Blog

Threat Score
70/100

Date Published: 2025-05-01

Date Updated: 2026-04-28

...
...

Insikt Group identified two new Golden Chickens malware families: TerraStealerV2, a browser- and wallet-focused stealer that collects Chrome credentials and extension/wallet data and exfiltrates to Telegram and a wetransfers.io endpoint, and TerraLogger, a standalone keylogger that writes keystrokes to local files; both are distributed via LNK/MSI/DLL/EXE and executed through trusted Windows utilities (regsvr32/mshta), show signs of active development, and include multiple observed samples and IOCs though TerraStealerV2 currently lacks Chrome ABE decryption and TerraLogger lacks built-in C2/exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.