Also known as: Golden Chickens, Venom Spider, tracked as, hyp3rlinx, ApparitionSec, Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, Mustang Panda, local, Gamaredon APT, APT34
Insikt Group identified four new malware families from TAG-195 (Golden Chickens, Venom Spider), a financially motivated malware-as-a-service developer. The families include TinyEgg, a lightweight initial-access backdoor; ChonkyChicken, which expands capabilities with browser credential theft and session automation; a modularized ChonkyChicken variant using controller-and-plugin architecture; and ChromEggscalator, a modified Chrome encryption-bypass tool. TAG-127 has been observed deploying TinyEgg via ClickFix campaigns using fake security verification pages. The modular architecture reduces static detection exposure and enables selective capability provisioning to operators. All families share consistent architectural traits including WebSocket command-and-control, Run key persistence, string obfuscation, and execution via legitimate Windows binaries. This represents a deliberate architectural transition toward operator-driven tooling within the TAG-195 MaaS ecosystem.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
TAG-195 (also known as Golden Chickens or Venom Spider) is a financially motivated threat group identified by Insikt Group. The group operates a malware-as-a-service (MaaS) ecosystem, distributing tools such as TinyEgg, ChonkyChicken, its modular variant, and ChromEggscalator. These malware families feature advanced capabilities for initial access, credential theft, persistence, and lateral movement, suggesting a sophisticated operator-driven toolkit designed to evade detection while enabling financial gain through cybercriminal activities.
Goals & Targeting
TAG-195's primary motivation is financial gain, as indicated by the nature of its malware and deployment methods. The group targets sectors that align with financial interests, likely focusing on industries where monetary extraction is feasible, such as finance, retail, and e-commerce. The use of ClickFix campaigns suggests targeting of consumers or organizations that receive a high volume of legitimate traffic, potentially making them easier to compromise. TAG-195's operator-driven tooling indicates it caters to cybercriminals seeking to monetize their activities, likely including ransomware operators or data thieves.
Enhanced Description
TAG-195 is a financially motivated threat group that has emerged as a notable player in the cybercrime landscape. The group operates a malware-as-a-service (MaaS) ecosystem, offering operators access to a range of tools designed for malicious activities. Insikt Group identified four distinct malware families associated with TAG-195: TinyEgg, ChonkyChicken, its modular variant, and ChromEggscalator. These tools are designed for different stages of the attack lifecycle, including initial access, credential theft, persistence, and lateral movement. The modular architecture of these tools allows operators to select specific capabilities, reducing detection risk while enhancing operational flexibility. TAG-195 has been observed deploying TinyEgg via ClickFix campaigns, leveraging fake security verification pages as a delivery mechanism. The group's malware families share consistent architectural traits, including WebSocket command-and-control (C2), Run key persistence, string obfuscation, and execution via legitimate Windows binaries. This design approach indicates a deliberate effort to create tools that are both effective and difficult for defenders to detect. TAG-195's operations demonstrate a clear focus on financial gain, with tools designed to facilitate theft of sensitive data, unauthorized access, and potentially other financially motivated activities.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TAG-195 has been observed deploying its malware in campaigns leveraging ClickFix as a delivery method, with fake security verification pages used to compromise victims. The modular architecture of the group's tools allows for selective capability provisioning, reducing the static detection footprint while increasing flexibility. This indicates a high level of operational maturity and suggests that TAG-195 is likely targeting organizations with less sophisticated defenses, leveraging financial motivations to maximize returns. Notable operations include the deployment of TinyEgg in ClickFix campaigns, highlighting the group's focus on scalable and reliable attack strategies.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the data is high due to detailed malware analysis by Insikt Group, including identification of architectural traits and deployment methods. However, there are gaps in understanding specific victims beyond ClickFix campaigns and the exact geographic targeting scope.
No campaigns linked yet.
No observed data linked yet.
32
Techniques
48
Tools
0
Campaigns
40
IOCs
0
Observed Data
11
Tactics