Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Upgrades MaaS Ecosystem with Modular Tools

7df85059c75bcd3e6280b4c60e1d75c094429664

TLP:CLEAR
Active

SHA-1 Hash

Description

Insikt Group identified four new malware families from TAG-195 (Golden Chickens, Venom Spider), a financially motivated malware-as-a-service developer. The families include TinyEgg, a lightweight initial-access backdoor; ChonkyChicken, which expands capabilities with browser credential theft and session automation; a modularized ChonkyChicken variant using controller-and-plugin architecture; and ChromEggscalator, a modified Chrome encryption-bypass tool. TAG-127 has been observed deploying TinyEgg via ClickFix campaigns using fake security verification pages. The modular architecture reduces static detection exposure and enables selective capability provisioning to operators. All families share consistent architectural traits including WebSocket command-and-control, Run key persistence, string obfuscation, and execution via legitimate Windows binaries. This represents a deliberate architectural transition toward operator-driven tooling within the TAG-195 MaaS ecosystem.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Upgrades MaaS Ecosystem with Modular Tools
Pattern Type
STIX
Confidence
75%
Valid From
Jul 24, 2026 02:00
Total Sightings
0
Added
Jul 24, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 7df85059c75bcd3e6280b4c60e1d75c094429664

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.