Upgrades MaaS Ecosystem with Modular Tools
released on 2026-07-23 @ 04:30:35 PM
Insikt Group identified four new malware families from TAG-195 (Golden Chickens, Venom Spider), a financially motivated malware-as-a-service developer. The families include TinyEgg, a lightweight initial-access backdoor; ChonkyChicken, which expands capabilities with browser credential theft and session automation; a modularized ChonkyChicken variant using controller-and-plugin architecture; and ChromEggscalator, a modified Chrome encryption-bypass tool. TAG-127 has been observed deploying TinyEgg via ClickFix campaigns using fake security verification pages. The modular architecture reduces static detection exposure and enables selective capability provisioning to operators. All families share consistent architectural traits including WebSocket command-and-control, Run key persistence, string obfuscation, and execution via legitimate Windows binaries. This represents a deliberate architectural transition toward operator-driven tooling within the TAG-195 MaaS ecosystem.