The Hacker News disclosed that the threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings.Recorded Future's Insikt Group, tracking the group as TAG-195, identified four new malware families: TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator. These new families represent an architectural evolution, sharing common command-and-control mechanisms, persistence approaches, string obfuscation, and delivery models. TinyEgg serves as a lightweight backdoor for initial access and host profiling, passing post-exploitation capabilities to ChonkyChicken. ChonkyChicken is a more advanced implant with features like browser credential theft and live browser session control. The modularized ChonkyChicken introduces a controller-and-plugin architecture, allowing for on-demand loading of 14 distinct capability modules, including process management, screen capture, keylogging, and browser theft. ChromEggscalator is a modified version of a publicly available Chrome encryption-bypass tool. This shift to modular, operator-driven tooling is seen as a move for defense evasion and to meet commercial incentives within the MaaS model, allowing selective provisioning of capabilities and reducing detection exposure.The Hacker News
Source: Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
