# ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome App-Bound Encryption via ChromEggscalator to Steal Browser Credentials

> TAG-195 (Golden Chickens/Venom Spider) has resurfaced with four new malware families — TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator — delivered via ClickFix Run-dialog social engineering. ChromEggscalator bypasses Chrome App-Bound Encryption to steal Chrome/Edge credentials, while ChonkyChicken adds keylogging, clipboard/audio/screenshot capture, Chrome DevTools Protocol session hijacking, port scanning, and lateral movement via remote scheduled tasks.

- **Published:** 2026-07-24T00:00:00Z
- **Last reviewed:** 2026-07-24T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1664
- **ID:** TL-2026-1664
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** TAG-195
- **Detections:** 9 · **IOCs:** 41 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Recorded Future's Insikt Group identified a sustained architectural transition in the TAG-195 (Golden Chickens, Venom Spider) malware-as-a-service ecosystem, historically known for More_eggs, Taurus Builder, TerraStealerV2, and TerraLogger. The new toolset comprises: TinyEgg, a lightweight first-stage backdoor delivered as an OCX file (updater.ocx) executed via regsvr32.exe that provides host profiling, an interactive shell, and persistence management over a WebSocket/JSON C2 protocol; ChonkyChicken, a fully-featured second-stage post-exploitation implant (mscomctl.ocx) that adds browser credential theft, CDP-based live session hijacking, keylogging, clipboard/audio/screenshot capture, network reconnaissance (ARP, NetBIOS, TCP port scan, SMB enumeration), and lateral movement via credential-backed remote execution and scheduled tasks; a modularized ChonkyChicken variant (koki.ocx/agent.ocx) using a controller-and-plugin architecture that loads at least 14 Base64-encoded capability modules on demand via LoadLibraryA, each exporting module_init/module_handle/module_cleanup, reducing the static detection footprint of the base implant; and ChromEggscalator (chromelevator.ocx), a modified derivative of the publicly available ChromElevator tool that resolves the APIs required to bypass Chrome's App-Bound Encryption and exfiltrate Chrome/Edge credential material and session data, staged and decoded via ChonkyChicken's chrome_upload command. All four families share a common request_register/agent_register WebSocket handshake, an agentType field distinguishing implant tiers, RFC 6455 frame masking that defeats content-based network signatures, OCX/regsvr32.exe abuse for execution, filename-gated execution (sandbox evasion), and a unified persistence mechanism via the HKCU\Software\Microsoft\Windows\CurrentVersion\Run\WinComCtl registry key with payloads staged under %LOCALAPPDATA%\Packages\. Initial access is achieved through ClickFix lures: a fake verification page (e.g. screenly[.]cam) instructs victims to copy a malicious command to the clipboard and paste it into the Windows Run dialog (T1204.004), which downloads and registers the first-stage OCX. ChonkyChicken's CDP session hijacking launches Chrome/Edge with --remote-debugging-port=9222, a custom --user-data-dir, and an off-screen --window-position=-32000,-32000 to silently drive the victim's authenticated browser sessions independent of stored credentials — defeating detections that rely solely on credential-store monitoring. TAG-195 operates as a financially motivated MaaS provider whose tooling has historically been used by FIN6, Cobalt Group, Evilnum, and TAG-127 (which uses ClickFix/VenomLNK delivery for these payloads), with cumulative attributed losses estimated at $1.5B across the broader Golden Chickens customer ecosystem. The identity behind the Golden Chickens MaaS operation is publicly attributed to the persona badbullzvenom.

## MITRE ATT&CK

- T1189 Drive-by Compromise
- T1204.004 Malicious Copy and Paste
- T1059.003 Windows Command Shell
- T1106 Native API
- T1547.001 Registry Run Keys / Startup Folder
- T1053.005 Scheduled Task
- T1218.010 Regsvr32
- T1140 Deobfuscate/Decode Files or Information
- T1027 Obfuscated Files or Information
- T1497 Virtualization/Sandbox Evasion
- T1620 Reflective Code Loading
- T1555.003 Credentials from Web Browsers
- T1539 Steal Web Session Cookie
- T1528 Steal Application Access Token
- T1056.001 Keylogging
- T1082 System Information Discovery
- T1046 Network Service Discovery
- T1135 Network Share Discovery
- T1087.002 Domain Account
- T1018 Remote System Discovery
- T1021 Remote Services
- T1113 Screen Capture
- T1115 Clipboard Data
- T1123 Audio Capture
- T1185 Browser Session Hijacking
- T1071.001 Web Protocols
- T1090 Proxy
- T1105 Ingress Tool Transfer
- T1095 Non-Application Layer Protocol
- T1587.001 Malware
- T1583.001 Domains

## Sources

- [ChonkyChicken Steals Chrome Credentials](https://cybersecuritynews.com/chonkychicken-steals-chrome-credentials/)
- [TAG-195 Upgrades MaaS Ecosystem with Modular Tools](https://www.recordedfuture.com/research/tag-195-evolves-maas-ecosystem)
- [Golden Chickens Resurfaces With Four New Malware Families and Modular Implants](https://thehackernews.com/2026/07/golden-chickens-resurfaces-with-four.html)
- [Golden Chickens Deploy TerraStealerV2 to Steal Browser Credentials and Crypto Wallet Data](https://thehackernews.com/2025/05/golden-chickens-deploy-terrastealerv2.html)
- [Golden Chickens Unveils TerraStealerV2 and TerraLogger: New Credential Theft Tools Identified by Insikt Group](https://www.recordedfuture.com/research/terrastealerv2-and-terralogger)
- [Golden Chickens are creating a new malware to steal passwords](https://cybernews.com/security/golden-chickens-new-malware-steal-passwords/)
- [Identity Reveal: Threat Actor Behind Golden Chicken Malware Service Exposed](https://heimdalsecurity.com/blog/threat-actor-exposed-golden-chicken-malware/)
- [Experts Uncover the Identity of Mastermind Behind Golden Chickens Malware Service](https://thehackernews.com/2023/01/experts-uncover-identity-of-mastermind.html)
- [Cybercrime: Golden Chicken Hatches More_eggs Backdoor](https://www.securityblue.team/blog/posts/cybercrime-golden-chicken-more-eggs-backdoor)
- [Golden Chickens: Uncovering A Malware-as-a-Service (MaaS) Provider and Two New Threat Actors Using It](https://medium.com/@quoscient/golden-chickens-uncovering-a-malware-as-a-service-maas-provider-and-two-new-threat-actors-using-61cf0cb87648)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1664
