ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome App-Bound Encryption via ChromEggscalator to Steal Browser Credentials — Threadlinqs Intelligence
As of 2026-07-24, ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome App-Bound Encryption via ChromEggscalator to Steal Browser Credentials is a high-severity malware threat attributed to TAG-195, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 41 indicators of compromise.
Threat ID: TL-2026-1664 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: TAG-195 · FINANCIAL
TAG-195 (Golden Chickens/Venom Spider) has resurfaced with four new malware families — TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator — delivered via ClickFix
Recorded Future's Insikt Group identified a sustained architectural transition in the TAG-195 (Golden Chickens, Venom Spider) malware-as-a-service ecosystem, historically known for More_eggs, Taurus Builder, TerraStealerV2, and TerraLogger. The new toolset comprises: TinyEgg, a lightweight first-stage backdoor delivered as an OCX file (updater.ocx) executed via regsvr32.exe that provides host profiling, an interactive shell, and persistence management over a WebSocket/JSON C2 protocol; ChonkyChicken, a fully-featured second-stage post-exploitation implant (mscomctl.ocx) that adds browser credential theft, CDP-based live session hijacking, keylogging, clipboard/audio/screenshot capture, network reconnaissance (ARP, NetBIOS, TCP port scan, SMB enumeration), and lateral movement via credential-backed remote execution and scheduled tasks; a modularized ChonkyChicken variant (koki.ocx/agent.ocx) using a controller-and-plugin architecture that loads at least 14 Base64-encoded capability modules on demand via LoadLibraryA, each exporting module_init/module_handle/module_cleanup, reducing the static detection footprint of the base implant; and ChromEggscalator (chromelevator.ocx), a modified derivative of the publicly available ChromElevator tool that resolves the APIs required to bypass Chrome's App-Bound Encryption and exfiltrate Chrome/Edge credential material and session data, staged and decoded via ChonkyChicken's chrome_upload command. All four families share a common request_register/agent_register WebSocket handshake, an agentType field distinguishing implant tiers, RFC 6455 frame masking that defeats content-based network signatures, OCX/regsvr32.exe abuse for execution, filename-gated execution (sandbox evasion), and a unified persistence mechanism via the HKCU\Software\Microsoft\Windows\CurrentVersion\Run\WinComCtl registry key with payloads staged under %LOCALAPPDATA%\Packages\. Initial access is achieved through ClickFix lures: a fake verification page (e.g. screenly[.]cam) instructs victims to copy a malicious command to the clipboard and paste it into the Windows Run dialog (T1204.004), which downloads and registers the first-stage OCX. ChonkyChicken's CDP session hijacking launches Chrome/Edge with --remote-debugging-port=9222, a custom --user-data-dir, and an off-screen --window-position=-32000,-32000 to silently drive the victim's authenticated browser sessions independent of stored credentials — defeating detections that rely solely on credential-store monitoring. TAG-195 operates as a financially motivated MaaS provider whose tooling has historically been used by FIN6, Cobalt Group, Evilnum, and TAG-127 (which uses ClickFix/VenomLNK delivery for these payloads), with cumulative attributed losses estimated at $1.5B across the broader Golden Chickens customer ecosystem. The identity behind the Golden Chickens MaaS operation is publicly attributed to the persona badbullzvenom.
Weaknesses (CWE)
CWE-522, CWE-311, CWE-494
Target sectors: financial services, technology, professional services, retail, general enterprise
Target regions: North America, Europe
Detections & IOCs
As of 2026-08-25, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 41 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1189, T1204.004, T1059.003, T1106, T1547.001, T1053.005, T1218.010, T1140, T1027, T1497