Threat reportMalwareTL-2026-1664

ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome App-Bound Encryption via ChromEggscalator to Steal Browser Credentials

highACTIVE

ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome (TL-2026-1664), also tracked as ChonkyChicken, is a high-severity malware campaign, first published 2026-07-24. It is attributed to TAG-195 with high confidence, affects Google Chrome, maps to 31 MITRE ATT&CK techniques (T1018, T1021, T1027), and is covered by 9 detection rules and 41 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
31MITRE ATT&CK
Actors
2TAG-195
Detection rules
9SPL · KQL · Sigma
IOCs
41Indicators of compromise

Key facts for TL-2026-1664

Threat ID
TL-2026-1664
Also known as
ChonkyChicken, ChromEggscalator, TinyEgg
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
TAG-195, GC01
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
financial services, technology, professional services, retail, general enterprise
Target regions
North America, Europe
Detection rules
9
Indicators of compromise
41

Malware and tooling in ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome

Malware and tooling: ChonkyChicken, ChromEggscalator, More_eggs, TerraStealerV2, Terralogger, TinyEgg, ChromElevator, Taurus Builder, WebSocket/JSON task-driven C2 (request_register/agent_register handshake)

How ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome works

TAG-195 (Golden Chickens/Venom Spider) has resurfaced with four new malware families — TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator — delivered via ClickFix Run-dialog social engineering. ChromEggscalator bypasses Chrome App-Bound Encryption to steal Chrome/Edge credentials, while ChonkyChicken adds keylogging, clipboard/audio/screenshot capture, Chrome DevTools Protocol session hijacking, port scanning, and lateral movement via remote scheduled tasks.

Recorded Future's Insikt Group identified a sustained architectural transition in the TAG-195 (Golden Chickens, Venom Spider) malware-as-a-service ecosystem, historically known for More_eggs, Taurus Builder, TerraStealerV2, and TerraLogger. The new toolset comprises: TinyEgg, a lightweight first-stage backdoor delivered as an OCX file (updater.ocx) executed via regsvr32.exe that provides host profiling, an interactive shell, and persistence management over a WebSocket/JSON C2 protocol; ChonkyChicken, a fully-featured second-stage post-exploitation implant (mscomctl.ocx) that adds browser credential theft, CDP-based live session hijacking, keylogging, clipboard/audio/screenshot capture, network reconnaissance (ARP, NetBIOS, TCP port scan, SMB enumeration), and lateral movement via credential-backed remote execution and scheduled tasks; a modularized ChonkyChicken variant (koki.ocx/agent.ocx) using a controller-and-plugin architecture that loads at least 14 Base64-encoded capability modules on demand via LoadLibraryA, each exporting module_init/module_handle/module_cleanup, reducing the static detection footprint of the base implant; and ChromEggscalator (chromelevator.ocx), a modified derivative of the publicly available ChromElevator tool that resolves the APIs required to bypass Chrome's App-Bound Encryption and exfiltrate Chrome/Edge credential material and session data, staged and decoded via ChonkyChicken's chrome_upload command. All four families share a common request_register/agent_register WebSocket handshake, an agentType field distinguishing implant tiers, RFC 6455 frame masking that defeats content-based network signatures, OCX/regsvr32.exe abuse for execution, filename-gated execution (sandbox evasion), and a unified persistence mechanism via the HKCU\Software\Microsoft\Windows\CurrentVersion\Run\WinComCtl registry key with payloads staged under %LOCALAPPDATA%\Packages\. Initial access is achieved through ClickFix lures: a fake verification page (e.g. screenly[.]cam) instructs victims to copy a malicious command to the clipboard and paste it into the Windows Run dialog (T1204.004), which downloads and registers the first-stage OCX. ChonkyChicken's CDP session hijacking launches Chrome/Edge with --remote-debugging-port=9222, a custom --user-data-dir, and an off-screen --window-position=-32000,-32000 to silently drive the victim's authenticated browser sessions independent of stored credentials — defeating detections that rely solely on credential-store monitoring. TAG-195 operates as a financially motivated MaaS provider whose tooling has historically been used by FIN6, Cobalt Group, Evilnum, and TAG-127 (which uses ClickFix/VenomLNK delivery for these payloads), with cumulative attributed losses estimated at $1.5B across the broader Golden Chickens customer ecosystem. The identity behind the Golden Chickens MaaS operation is publicly attributed to the persona badbullzvenom.

MITRE ATT&CK techniques used in TL-2026-1664

Discovery

T1018 Remote System Discovery; T1046 Network Service Discovery; T1082 System Information Discovery; T1087.002 Domain Account; T1135 Network Share Discovery

Lateral Movement

T1021 Remote Services

Defense Evasion

T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1218.010 Regsvr32; T1497 Virtualization/Sandbox Evasion; T1620 Reflective Code Loading

Persistence

T1053.005 Scheduled Task; T1547.001 Registry Run Keys / Startup Folder

Credential Access

T1056.001 Keylogging; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers

Execution

T1059.003 Windows Command Shell; T1106 Native API; T1204.004 Malicious Copy and Paste

Command and Control

T1071.001 Web Protocols; T1090 Proxy; T1095 Non-Application Layer Protocol; T1105 Ingress Tool Transfer

Collection

T1113 Screen Capture; T1115 Clipboard Data; T1123 Audio Capture; T1185 Browser Session Hijacking

Initial Access

T1189 Drive-by Compromise

Resource Development

T1583.001 Domains; T1587.001 Malware

Affected products and versions in ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome

  • Google — Chrome
    Vulnerable versions: all versions using App-Bound Encryption for credential storage
  • Microsoft — Edge
    Vulnerable versions: all Chromium-based versions using App-Bound Encryption equivalent
  • Microsoft — Windows
    Vulnerable versions: Windows 10; Windows 11

Remediation for ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome

Immediate actions

  • Block delivery/lure domains: screenly.cam, aurekh.com, ahdaratlegalservices.com, paysolutions.ink
  • Block C2 domains xtrafftrck.net, thessa.trackgrid.net, api.it195f.top and IPs 70.34.205.43, 65.20.102.161, 65.20.105.177, 108.61.209.100
  • Alert on regsvr32.exe executing OCX files from %TEMP%, %LOCALAPPDATA%\Packages\, or %AppData% paths
  • Alert on chrome.exe/msedge.exe launched with --remote-debugging-port and off-screen --window-position arguments
  • Hunt for HKCU\Software\Microsoft\Windows\CurrentVersion\Run\WinComCtl registry value
  • Force-close and re-authenticate any browser session observed with an active CDP remote-debugging listener on 127.0.0.1:9222

Workarounds

  • Disable the Windows Run dialog via Group Policy for high-risk user segments
  • Enable Chrome/Edge managed policy to disable --remote-debugging-port and restrict DevTools Protocol access

Longer-term hardening

  • Deploy Group Policy / attack-surface-reduction rules to restrict clipboard-to-Run-dialog execution patterns (block Win+R paste-and-execute of encoded commands)
  • Enforce application allow-listing to prevent unsigned/unexpected OCX registration via regsvr32.exe
  • Deploy EDR behavioral detection for WebSocket C2 with RFC 6455 masked frames and JSON task-driven protocols
  • User awareness training specifically targeting ClickFix / fake CAPTCHA verification social engineering
  • Restrict local admin rights to reduce scheduled-task-based lateral movement blast radius

Weaknesses (CWE) in ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome

CWE-522, CWE-311, CWE-494

Timeline of ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome

  • Golden Chickens' More_eggs JavaScript downloader used in LinkedIn spear-phishing campaigns targeting business professionals with fake job offers.
  • QuoScient publishes research uncovering Golden Chickens as a malware-as-a-service provider used by multiple distinct threat actors.
  • eSentire and other researchers publicly attribute the Golden Chickens MaaS operation to the persona badbullzvenom, tied to individuals based in Moldova and Montreal, Canada.
  • Insikt Group documents TerraStealerV2 (lacking Chrome ABE bypass) and TerraLogger (lacking C2 capability) as the prior generation of Golden Chickens credential-theft tooling.
  • Golden Chickens observed deploying TerraStealerV2 to steal browser credentials and crypto wallet data.
  • ChromElevator, the publicly available Chrome credential-theft tool later modified into ChromEggscalator, is referenced in reporting on the StealIT malware ecosystem.
  • Insikt Group internal detection rules for ChromEggscalator execution behavior are dated, indicating analysis of the implant was underway ahead of public disclosure.
  • Insikt Group detection rules/sigma signatures for ChonkyChicken and its lg.txt logging artifact are dated, indicating the implant was already under active analysis roughly ten weeks before public reporting.
  • Cyber Security News, The Hacker News, and Cybernews publish coverage of the ChonkyChicken/ChromEggscalator campaign and its Chrome App-Bound Encryption bypass capability.
  • Recorded Future Insikt Group publishes research identifying four new TAG-195 malware families: TinyEgg, ChonkyChicken, modularized ChonkyChicken, and ChromEggscalator, representing a deliberate architectural transition to modular, operator-driven tooling.

Sources cited for ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome

Detection coverage for TL-2026-1664

As of 2026-07-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1664 across Splunk SPL, Microsoft KQL and Sigma, covering 41 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
41 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-1664

2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats