"The four new families indicate an architectural transition and evolution in the TAG-195 MaaS ecosystem," Recorded Future said.
Recorded Future on TAG-195 and the Golden Chickens ecosystem
Recorded Future's Insikt Group is tracking a financially motivated malware-as-a-service (MaaS) developer under the moniker TAG-195 and reports the group has resurfaced with four newly observed malware families. The developer operates inside an ecosystem long linked to the Golden Chickens service — also referred to as Venom Spider — and its tooling has previously been associated with both operators and customers identified as TAG-127.
The four new malware families in plain terms
Recorded Future summarizes the newly observed tools as TinyEgg, ChonkyChicken, a modularized ChonkyChicken, and ChromEggscalator. Each serves a distinct role within attack campaigns: TinyEgg is described as a lightweight initial-access backdoor; ChonkyChicken is a full-featured implant that expands on TinyEgg's capabilities; the modularized ChonkyChicken converts much of that functionality into on-demand components; and ChromEggscalator is a credential-theft successor to TerraStealerV2 and a modified implementation of a publicly available tool named ChromElevator.
Delivery, command-and-control, and sandbox evasion
Recorded Future links several attack chains to ClickFix-style social engineering campaigns and to another delivery method named VenomLNK. In documented cases, ClickFix lures have been used to convince targets to manually execute malicious commands that download and run OCX payloads from attacker-controlled staging infrastructure, ultimately installing TinyEgg. TinyEgg's role is focused on initial access and host profiling; post-exploitation functions are handed off to ChonkyChicken.
Technically, the malware establishes command-and-control (C2) communications over WebSockets to provide an interactive command shell. Operators can send input to the active shell session and receive output back, and the C2 channel is used to stage OCX payloads. TinyEgg is also designed to terminate execution when it detects sandboxing or automated analysis environments, a deliberate defensive measure against security research and automated detection.
Modular ChonkyChicken: 14 on-demand components and a mystery 'wtrack'
The modularized ChonkyChicken introduces a controller-and-plugin architecture that lets the controller fetch and load discrete capability modules from C2 infrastructure as needed. Recorded Future lists 14 modules available to operators: process management; screen capture and monitor enumeration; file manipulation; command execution; network reconnaissance; domain-based reconnaissance; clipboard capture; keylogging; audio capture; idle time check; HTTP/S requests via host; browser theft via ChromEggscalator; and persistence management.
One module, named "wtrack," has an undefined purpose in the reporting, which Recorded Future says suggests an active capability still under development. The firm further notes that the modular approach reduces the static footprint of a base implant and permits operators to selectively provision or withhold functionality — a change that Recorded Future characterizes as both an evasion tactic and a commercial feature aligned with the MaaS model.
How TAG-127, Cobalt Group, Evilnum, FIN6, and security teams are implicated
- TAG-127 and delivery methods: Recorded Future reports TAG-127 as both an operator and a customer within the same ecosystem and specifically observes TAG-127 deploying TinyEgg via ClickFix-style campaigns. TAG-127 is therefore directly implicated in using TAG-195 tooling for initial access.
- Cobalt Group, Evilnum, and FIN6: The report notes that tooling associated with a family called More_eggs — connected to the Golden Chickens ecosystem — has been used by these named groups. That linkage demonstrates cross-pollination of capabilities between TAG-195's MaaS offerings and other criminal operators.
- Security teams and defenders: The shift to modular, operator-driven implants, WebSocket-based interactive shells, and sandbox-evasion checks increases both the need to monitor delivery chains (ClickFix, VenomLNK, OCX payload hosting) and to inspect runtime behavior. Recorded Future highlights that modularization "almost certainly reduces the base implant's static detection exposure," a change defenders must account for in detection, response, and threat-hunting playbooks.
Recorded Future's findings portray an active developer refining its product: a compact initial-access backdoor, a feature-rich implant, pluginized modules to deliver capabilities on demand, and a browser-theft successor built from known tools. The presence of an unfinished "wtrack" module and the explicit design choices for evasion and selective provisioning underscore that TAG-195's evolution is operationally driven — and engineered to be consumable by other criminal groups. For defenders and those tracking criminal tool markets, the immediate questions are concrete: which delivery lures will be reused next, how widely the modular controller will be distributed, and when the "wtrack" capability will appear in live campaigns.
https://thehackernews.com/2026/07/golden-chickens-resurfaces-with-four.html




