TAG-195 Deploys ChonkyChicken Modular Malware Framework

TAG-195 ClickFix infection chain flowchart detailing TinyEgg and ChonkyChicken deployment
TAG-195 threat group associations (Source: Recorded Future)

Evolution of the Golden Chickens Ecosystem

Cybercriminals operating within the TAG-195 ecosystem have fundamentally restructured their malware architecture, adopting a highly modular approach. Consequently, compromised systems now only receive the specific functionalities required for an immediate operation. This strategic shift significantly complicates detection efforts and allows operators to conceal the full extent of their capabilities from security analysts.

Researchers from Insikt Group recently identified four novel malware families associated with TAG-195, a group also recognized under the aliases Golden Chickens and Venom Spider. The newly discovered arsenal includes TinyEgg, ChonkyChicken, a heavily modularized variant of ChonkyChicken, and ChromEggscalator. Notably, TAG-195 operates predominantly as a Malware-as-a-Service (MaaS) provider, supplying these advanced tools to other prominent cybercriminal syndicates.

The ClickFix Infection Vector

Attackers initiate the compromise sequence utilizing a deceptive ClickFix technique. Victims encounter a fraudulent webpage masquerading as a standard security check, superficially resembling a CAPTCHA verification prompt. The site instructs the user to paste a specific command directly into the Windows Run dialog or terminal.

This executed command silently downloads a malicious OCX file, subsequently executing it utilizing the legitimate Windows regsvr32.exe utility. This sophisticated “Living off the Land” (LotL) approach successfully bypasses conventional email security gateways and file filters that typically intercept malicious attachments.

From TinyEgg to ChonkyChicken

The initial payload deployed to the target machine is TinyEgg. This compact reconnaissance tool aggregates system telemetry, establishes a remote command shell for the attackers, and ensures persistent execution within the Windows environment. Once the compromised device registers with the command-and-control (C2) infrastructure, TinyEgg can download the far more robust ChonkyChicken payload, exponentially expanding the attackers’ operational capabilities.

ChonkyChicken acts as a comprehensive espionage suite. It systematically extracts credentials stored within web browsers, intercepts clipboard contents, records keystrokes, captures environmental audio, and continuously logs desktop screenshots. Furthermore, it actively scans for adjacent devices on the local network, facilitating lateral movement across corporate infrastructures.

Crucially, the malware can launch Google Chrome and Microsoft Edge in remote debugging mode, effectively hijacking the user’s active session. In such scenarios, a simple password reset remains insufficient to sever the attackers’ access.

ChromEggscalator and Modular Architecture

To bypass modern browser security mechanisms, TAG-195 engineers heavily modified the open-source ChromElevator tool, rebranding it as ChromEggscalator. The developers stripped the original command-line interface, packaged the resulting binary into an OCX file, and seamlessly integrated it into the ChonkyChicken data exfiltration chain.

The most profound architectural shift is evident in the modular iteration of ChonkyChicken. The core executable now functions solely as a lightweight C2 communication beacon, dynamically downloading specific plugins as needed. Analysts have identified at least 14 distinct modules governing file manipulation, process injection, credential theft, network pivoting, browser hijacking, microphone surveillance, screen capturing, and remote command execution. Because these components are fetched strictly upon operator request, the baseline executable contains minimal suspicious code, evading static heuristic analysis.

Evasion Techniques and Mitigation Strategies

All four identified families exhibit sophisticated evasion behaviors. They dynamically verify their own filenames prior to execution, establish persistence via identical registry modifications, and heavily abuse native Windows utilities. For C2 communications, both TinyEgg and ChonkyChicken utilize the WebSocket protocol, which significantly obfuscates malicious network traffic against traditional signature-based detection mechanisms.

Security professionals are strongly advised to meticulously monitor the execution of regsvr32.exe, particularly when invoking files originating from temporary directories or user profiles. Analysts must remain vigilant for the sudden appearance of unexpected OCX files, anomalous autorun registry modifications, and instances of web browsers launching with remote debugging flags enabled. Above all, organizations must educate users to immediately flag any webpage that demands manual command execution to pass a purported security verification.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply