Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors tag-195

Also known as: Golden Chickens, Venom Spider, tracked as, hyp3rlinx, ApparitionSec, Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, Mustang Panda, local, Gamaredon APT, APT34

Description

Insikt Group identified four new malware families from TAG-195 (Golden Chickens, Venom Spider), a financially motivated malware-as-a-service developer. The families include TinyEgg, a lightweight initial-access backdoor; ChonkyChicken, which expands capabilities with browser credential theft and session automation; a modularized ChonkyChicken variant using controller-and-plugin architecture; and ChromEggscalator, a modified Chrome encryption-bypass tool. TAG-127 has been observed deploying TinyEgg via ClickFix campaigns using fake security verification pages. The modular architecture reduces static detection exposure and enables selective capability provisioning to operators. All families share consistent architectural traits including WebSocket command-and-control, Run key persistence, string obfuscation, and execution via legitimate Windows binaries. This represents a deliberate architectural transition toward operator-driven tooling within the TAG-195 MaaS ecosystem.

Goals & Targeting

Targeted Sectors

Government
Defense
Energy
Financial services
Telecommunications
Critical infrastructure
Healthcare
Non profit
Maritime
Think tank
Transportation
Media
Aviation
Information technology
Education
Manufacturing
Aerospace
Food agriculture
Construction
Utilities
Retail
Mining
Hospitality

Targeted Countries / Regions

CN
RU
UA
TW
PL
IN
KR
US
KP
BY
PK
MX
IR
AZ
AE
SA
ES
VN
LB
AU
JP
CA

AI Analysis

· 1 week ago

Executive Summary

TAG-195 (also known as Golden Chickens or Venom Spider) is a financially motivated threat group identified by Insikt Group. The group operates a malware-as-a-service (MaaS) ecosystem, distributing tools such as TinyEgg, ChonkyChicken, its modular variant, and ChromEggscalator. These malware families feature advanced capabilities for initial access, credential theft, persistence, and lateral movement, suggesting a sophisticated operator-driven toolkit designed to evade detection while enabling financial gain through cybercriminal activities.

Goals & Targeting

TAG-195's primary motivation is financial gain, as indicated by the nature of its malware and deployment methods. The group targets sectors that align with financial interests, likely focusing on industries where monetary extraction is feasible, such as finance, retail, and e-commerce. The use of ClickFix campaigns suggests targeting of consumers or organizations that receive a high volume of legitimate traffic, potentially making them easier to compromise. TAG-195's operator-driven tooling indicates it caters to cybercriminals seeking to monetize their activities, likely including ransomware operators or data thieves.

Enhanced Description

TAG-195 is a financially motivated threat group that has emerged as a notable player in the cybercrime landscape. The group operates a malware-as-a-service (MaaS) ecosystem, offering operators access to a range of tools designed for malicious activities. Insikt Group identified four distinct malware families associated with TAG-195: TinyEgg, ChonkyChicken, its modular variant, and ChromEggscalator. These tools are designed for different stages of the attack lifecycle, including initial access, credential theft, persistence, and lateral movement. The modular architecture of these tools allows operators to select specific capabilities, reducing detection risk while enhancing operational flexibility. TAG-195 has been observed deploying TinyEgg via ClickFix campaigns, leveraging fake security verification pages as a delivery mechanism. The group's malware families share consistent architectural traits, including WebSocket command-and-control (C2), Run key persistence, string obfuscation, and execution via legitimate Windows binaries. This design approach indicates a deliberate effort to create tools that are both effective and difficult for defenders to detect. TAG-195's operations demonstrate a clear focus on financial gain, with tools designed to facilitate theft of sensitive data, unauthorized access, and potentially other financially motivated activities.

Key Capabilities

  • TinyEgg - Lightweight initial-access backdoor
  • ChonkyChicken - Browser credential theft and session automation
  • Modularized ChonkyChicken variant with controller-and-plugin architecture
  • ChromEggscalator - Modified Chrome encryption-bypass tool
  • WebSocket command-and-control communication
  • Run key persistence mechanisms
  • String obfuscation techniques
  • Execution via legitimate Windows binaries

MITRE ATT&CK Tactics

Initial Access
Credential Access
Lateral Movement
Exfiltration/Collection
Reconnaissance

ATT&CK Techniques

T1059.003 - Powershell command line option - Non-native use of rundll32.exe with arguments to execute code
T1078.001 - Application Layer Protocol - HTTP servers (for C2 communication)
T1566.001 - Credentials from Browser: Webrowser Stealing
T1059.004 - Powershell command line option - Use of encoded or Base64 arguments to execute code
T1207 - Windows Management Instrumentation (WMI)
T1569.002 - Valid Accounts: Email accounts

Software / Tooling

TinyEgg
ChonkyChicken
Modular ChonkyChicken
ChromEggscalator

Campaigns & Victims

TAG-195 has been observed deploying its malware in campaigns leveraging ClickFix as a delivery method, with fake security verification pages used to compromise victims. The modular architecture of the group's tools allows for selective capability provisioning, reducing the static detection footprint while increasing flexibility. This indicates a high level of operational maturity and suggests that TAG-195 is likely targeting organizations with less sophisticated defenses, leveraging financial motivations to maximize returns. Notable operations include the deployment of TinyEgg in ClickFix campaigns, highlighting the group's focus on scalable and reliable attack strategies.

IOC Patterns

  • Spear-phishing emails with malicious links leading to ClickFix pages
  • Malicious WebSocket traffic for C2 communication
  • Process injected into legitimate Windows binaries (e.g., rundll32.exe)
  • Obfuscated strings in executables associated with TAG-195 malware families
  • Presence of Run key registry entries for persistence

Recommended Actions

  • Enhance email filtering and phishing detection mechanisms to block malicious links and payloads.
  • Monitor network traffic for WebSocket communication indicative of C2 activities.
  • Implement endpoint detection and response (EDR) solutions to detect and mitigate in-memory malware execution.
  • Regularly update and patch legitimate Windows binaries to prevent attackers from leveraging them as part of their attack chain.
  • Educate users about suspicious security verification pages and the risks of clicking on unfamiliar links.
  • Conduct regular log analysis for signs of persistence mechanisms like Run key modifications.

Suggested Tags

Finances
MaaS
Cybercrime
Ransomware
Malware Families
Click-Fix Campaigns

Confidence Assessment

Confidence in the data is high due to detailed malware analysis by Insikt Group, including identification of architectural traits and deployment methods. However, there are gaps in understanding specific victims beyond ClickFix campaigns and the exact geographic targeting scope.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: hyp3rlinx
  2. attack.mitre.org — Cited by web research for: local
  3. www.recordedfuture.com — Cited by web research for: T1189

Intel Summary

32

Techniques

48

Tools

0

Campaigns

40

IOCs

0

Observed Data

11

Tactics

Tags

Finances
MaaS
Cybercrime
Ransomware
Malware Families
Click-Fix Campaigns

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
55%
Added
Jul 24, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.