TAG-195 Upgrades MaaS Ecosystem with Modular Tools
ID: ae753a7a-0b03-5bfe-970b-cecf2e277883
STIX ID: report--ae753a7a-0b03-5bfe-970b-cecf2e277883
Feed Name: Recorded Future Blog
Insikt Group documents four newly observed TAG-195 malware families — TinyEgg, ChonkyChicken, a modular ChonkyChicken variant, and ChromEggscalator — describing a shift to a modular MaaS architecture that enables WebSocket-based C2, ClickFix social-engineering delivery via regsvr32-executed OCX payloads, Chrome ABE bypass for browser credential theft, extensive reconnaissance/lateral-movement and surveillance capabilities, and provides IoCs, YARA/Sigma rules, and mitigation guidance for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
