Golden Chickens is a financially motivated cybercrime malware-as-a-service operator and developer best known for the More_eggs malware ecosystem. The group is widely tracked under aliases including Venom Spider, Skeleton Spider, TA4557, Storm-0538, TAG-195, and Camouflage Tempest. Reporting has also associated the cluster with names such as Gold Franklin, ITG08, Taal, and Magecart Group 6, though alias usage varies by vendor and some labels may reflect overlapping tracking rather than perfectly identical scoping. Golden Chickens develops and maintains modular intrusion tooling that is used both directly and by customer threat actors. Its malware has been linked to financially motivated groups including FIN6, Cobalt Group, Evilnum, and TAG-127. The ecosystem is notable for commercialized access and post-exploitation capability delivery, with tooling sold or provided to a select criminal customer base rather than tied to a single intrusion set. The actor is strongly associated with More_eggs, a JavaScript backdoor used for initial access, profiling, persistence, and follow-on payload delivery. More recent activity shows continued development of the ecosystem through additional malware families including TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator. These families indicate an architectural shift toward modular, operator-driven tooling with shared command-and-control patterns, persistence approaches, obfuscation methods, and delivery models. TinyEgg has been used as a lightweight initial-access backdoor for host profiling and shell access, while ChonkyChicken expands capability into browser credential theft, browser session control, reconnaissance, remote execution, and surveillance. The modular ChonkyChicken design supports on-demand loading of discrete capability modules, improving flexibility and likely reducing static detection exposure. ChromEggscalator has been described as a customized browser credential theft helper derived from publicly available Chrome encryption-bypass tooling. Golden Chickens commonly relies on social engineering and lure-based delivery. The group’s operations have repeatedly targeted human resources and recruiting workflows, including fake job application and résumé themes. Associated campaigns have used malicious shortcut files, archive-based lures, JavaScript payloads, living-off-the-land execution chains, and ClickFix-style user-execution prompts. Observed tradecraft includes heavy obfuscation, staged payload delivery, abuse of legitimate Windows utilities, persistence via Registry Run keys, and anti-analysis checks in early-stage implants. Victimology is primarily opportunistic and financially motivated, with tooling deployed by criminal operators against enterprises in sectors such as retail, hospitality, finance, and corporate environments where credential theft, payment-card theft, or broader monetization opportunities exist. Golden Chickens is not generally characterized as a nation-state actor; it is best understood as a cybercriminal service provider whose malware supports intrusion, credential theft, and downstream fraud or ransomware-adjacent operations. The group’s significance lies in its role as an enabler within the cybercrime ecosystem. Rather than being defined solely by one campaign, Golden Chickens functions as a persistent malware supplier whose evolving toolsets support multiple intrusion actors across successive generations of financially motivated operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
55 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
38 malware families attributed to this actor across reporting.
33 additional families tracked in Mallory.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
Carberp has exploited multiple Windows vulnerabilities (CVE-2010-2743, CVE-2010-3338, CVE-2010-4398, CVE-2008-1084) and a .NET Runtime Optimization vulnerability for privilege escalation.
FIN6 ... targeted CVE-2013-3660, CVE-2011-2005, and CVE-2010-4398, all of which could allow local users to access kernel-level privileges.
FIN6 ... targeted CVE-2013-3660, CVE-2011-2005, and CVE-2010-4398, all of which could allow local users to access kernel-level privileges.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
The following analytic detects when su runs from a page-cache-corrupted binary... This activity is significant because it indicates a possible privilege escalation attempt, allowing a user to gain root access... CVE CVE-2026-31431 ... References ... copy-fail-CVE-2026-31431
1 more CVE tied to this actor tracked in Mallory.
101 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operators behind the Golden Chickens malware-as-a-service ecosystem resurfaced with four new malware families and are evolving toward modular, operator-driven tooling for initial access, credential theft, browser session control, keylogging, screen capture, and other post-exploitation capabilities.
Financially motivated malware-as-a-service developer resurfacing with four new malware families and transitioning to modular, operator-driven tooling for defense evasion and selective capability delivery.
Mentioned as a criminal group previously linked in public reporting to TAG-195 tooling.
Financially motivated threat group using job-seeker impersonation on professional platforms to deliver malware via fake résumé links.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.