Threat reportMalwareTL-2026-1664
ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome App-Bound Encryption via ChromEggscalator to Steal Browser Credentials
ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome (TL-2026-1664), also tracked as ChonkyChicken, is a high-severity malware campaign, first published 2026-07-24. It is attributed to TAG-195 with high confidence, affects Google Chrome, maps to 31 MITRE ATT&CK techniques (T1018, T1021, T1027), and is covered by 9 detection rules and 41 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 31MITRE ATT&CK
- Actors
- 2TAG-195
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 41Indicators of compromise
Key facts for TL-2026-1664
- Threat ID
- TL-2026-1664
- Also known as
- ChonkyChicken, ChromEggscalator, TinyEgg
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- TAG-195, GC01
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- financial services, technology, professional services, retail, general enterprise
- Target regions
- North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 41
Malware and tooling in ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome
Malware and tooling: ChonkyChicken, ChromEggscalator, More_eggs, TerraStealerV2, Terralogger, TinyEgg, ChromElevator, Taurus Builder, WebSocket/JSON task-driven C2 (request_register/agent_register handshake)
How ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome works
TAG-195 (Golden Chickens/Venom Spider) has resurfaced with four new malware families — TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator — delivered via ClickFix Run-dialog social engineering. ChromEggscalator bypasses Chrome App-Bound Encryption to steal Chrome/Edge credentials, while ChonkyChicken adds keylogging, clipboard/audio/screenshot capture, Chrome DevTools Protocol session hijacking, port scanning, and lateral movement via remote scheduled tasks.
Recorded Future's Insikt Group identified a sustained architectural transition in the TAG-195 (Golden Chickens, Venom Spider) malware-as-a-service ecosystem, historically known for More_eggs, Taurus Builder, TerraStealerV2, and TerraLogger. The new toolset comprises: TinyEgg, a lightweight first-stage backdoor delivered as an OCX file (updater.ocx) executed via regsvr32.exe that provides host profiling, an interactive shell, and persistence management over a WebSocket/JSON C2 protocol; ChonkyChicken, a fully-featured second-stage post-exploitation implant (mscomctl.ocx) that adds browser credential theft, CDP-based live session hijacking, keylogging, clipboard/audio/screenshot capture, network reconnaissance (ARP, NetBIOS, TCP port scan, SMB enumeration), and lateral movement via credential-backed remote execution and scheduled tasks; a modularized ChonkyChicken variant (koki.ocx/agent.ocx) using a controller-and-plugin architecture that loads at least 14 Base64-encoded capability modules on demand via LoadLibraryA, each exporting module_init/module_handle/module_cleanup, reducing the static detection footprint of the base implant; and ChromEggscalator (chromelevator.ocx), a modified derivative of the publicly available ChromElevator tool that resolves the APIs required to bypass Chrome's App-Bound Encryption and exfiltrate Chrome/Edge credential material and session data, staged and decoded via ChonkyChicken's chrome_upload command. All four families share a common request_register/agent_register WebSocket handshake, an agentType field distinguishing implant tiers, RFC 6455 frame masking that defeats content-based network signatures, OCX/regsvr32.exe abuse for execution, filename-gated execution (sandbox evasion), and a unified persistence mechanism via the HKCU\Software\Microsoft\Windows\CurrentVersion\Run\WinComCtl registry key with payloads staged under %LOCALAPPDATA%\Packages\. Initial access is achieved through ClickFix lures: a fake verification page (e.g. screenly[.]cam) instructs victims to copy a malicious command to the clipboard and paste it into the Windows Run dialog (T1204.004), which downloads and registers the first-stage OCX. ChonkyChicken's CDP session hijacking launches Chrome/Edge with --remote-debugging-port=9222, a custom --user-data-dir, and an off-screen --window-position=-32000,-32000 to silently drive the victim's authenticated browser sessions independent of stored credentials — defeating detections that rely solely on credential-store monitoring. TAG-195 operates as a financially motivated MaaS provider whose tooling has historically been used by FIN6, Cobalt Group, Evilnum, and TAG-127 (which uses ClickFix/VenomLNK delivery for these payloads), with cumulative attributed losses estimated at $1.5B across the broader Golden Chickens customer ecosystem. The identity behind the Golden Chickens MaaS operation is publicly attributed to the persona badbullzvenom.
MITRE ATT&CK techniques used in TL-2026-1664
Discovery
T1018 Remote System Discovery; T1046 Network Service Discovery; T1082 System Information Discovery; T1087.002 Domain Account; T1135 Network Share Discovery
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1218.010 Regsvr32; T1497 Virtualization/Sandbox Evasion; T1620 Reflective Code Loading
Persistence
T1053.005 Scheduled Task; T1547.001 Registry Run Keys / Startup Folder
Credential Access
T1056.001 Keylogging; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers
Execution
T1059.003 Windows Command Shell; T1106 Native API; T1204.004 Malicious Copy and Paste
Command and Control
T1071.001 Web Protocols; T1090 Proxy; T1095 Non-Application Layer Protocol; T1105 Ingress Tool Transfer
Collection
T1113 Screen Capture; T1115 Clipboard Data; T1123 Audio Capture; T1185 Browser Session Hijacking
Initial Access
Resource Development
Affected products and versions in ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome
Remediation for ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome
Immediate actions
- Block delivery/lure domains: screenly.cam, aurekh.com, ahdaratlegalservices.com, paysolutions.ink
- Block C2 domains xtrafftrck.net, thessa.trackgrid.net, api.it195f.top and IPs 70.34.205.43, 65.20.102.161, 65.20.105.177, 108.61.209.100
- Alert on regsvr32.exe executing OCX files from %TEMP%, %LOCALAPPDATA%\Packages\, or %AppData% paths
- Alert on chrome.exe/msedge.exe launched with --remote-debugging-port and off-screen --window-position arguments
- Hunt for HKCU\Software\Microsoft\Windows\CurrentVersion\Run\WinComCtl registry value
- Force-close and re-authenticate any browser session observed with an active CDP remote-debugging listener on 127.0.0.1:9222
Workarounds
- Disable the Windows Run dialog via Group Policy for high-risk user segments
- Enable Chrome/Edge managed policy to disable --remote-debugging-port and restrict DevTools Protocol access
Longer-term hardening
- Deploy Group Policy / attack-surface-reduction rules to restrict clipboard-to-Run-dialog execution patterns (block Win+R paste-and-execute of encoded commands)
- Enforce application allow-listing to prevent unsigned/unexpected OCX registration via regsvr32.exe
- Deploy EDR behavioral detection for WebSocket C2 with RFC 6455 masked frames and JSON task-driven protocols
- User awareness training specifically targeting ClickFix / fake CAPTCHA verification social engineering
- Restrict local admin rights to reduce scheduled-task-based lateral movement blast radius
Weaknesses (CWE) in ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome
Timeline of ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome
- Golden Chickens' More_eggs JavaScript downloader used in LinkedIn spear-phishing campaigns targeting business professionals with fake job offers.
- QuoScient publishes research uncovering Golden Chickens as a malware-as-a-service provider used by multiple distinct threat actors.
- eSentire and other researchers publicly attribute the Golden Chickens MaaS operation to the persona badbullzvenom, tied to individuals based in Moldova and Montreal, Canada.
- Insikt Group documents TerraStealerV2 (lacking Chrome ABE bypass) and TerraLogger (lacking C2 capability) as the prior generation of Golden Chickens credential-theft tooling.
- Golden Chickens observed deploying TerraStealerV2 to steal browser credentials and crypto wallet data.
- ChromElevator, the publicly available Chrome credential-theft tool later modified into ChromEggscalator, is referenced in reporting on the StealIT malware ecosystem.
- Insikt Group internal detection rules for ChromEggscalator execution behavior are dated, indicating analysis of the implant was underway ahead of public disclosure.
- Insikt Group detection rules/sigma signatures for ChonkyChicken and its lg.txt logging artifact are dated, indicating the implant was already under active analysis roughly ten weeks before public reporting.
- Cyber Security News, The Hacker News, and Cybernews publish coverage of the ChonkyChicken/ChromEggscalator campaign and its Chrome App-Bound Encryption bypass capability.
- Recorded Future Insikt Group publishes research identifying four new TAG-195 malware families: TinyEgg, ChonkyChicken, modularized ChonkyChicken, and ChromEggscalator, representing a deliberate architectural transition to modular, operator-driven tooling.
Sources cited for ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome
- ChonkyChicken Steals Chrome Credentials
- TAG-195 Upgrades MaaS Ecosystem with Modular Tools
- Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
- Golden Chickens Deploy TerraStealerV2 to Steal Browser Credentials and Crypto Wallet Data
- Golden Chickens Unveils TerraStealerV2 and TerraLogger: New Credential Theft Tools Identified by Insikt Group
- Golden Chickens are creating a new malware to steal passwords
- Identity Reveal: Threat Actor Behind Golden Chicken Malware Service Exposed
- Experts Uncover the Identity of Mastermind Behind Golden Chickens Malware Service
- Cybercrime: Golden Chicken Hatches More_eggs Backdoor
- Golden Chickens: Uncovering A Malware-as-a-Service (MaaS) Provider and Two New Threat Actors Using It
Detection coverage for TL-2026-1664
As of 2026-07-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1664 across Splunk SPL, Microsoft KQL and Sigma, covering 41 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1664
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.