🟠 High | Source: The Hacker News
The Golden Chickens threat group, operators of a well-established Malware-as-a-Service platform, has introduced four new malware families including TinyEgg, ChonkyChicken, a modular ChonkyChicken variant, and a browser credential stealer. Despite significant public exposure of their operations, the group continues to evolve and expand their toolset. This demonstrates that public disclosure alone is insufficient to disrupt financially motivated MaaS operators.
Security Architect’s Take: Prioritise enforcement of application allowlisting and browser credential protection controls — particularly for enterprise browsers accessing cloud consoles — since the credential-stealing component could facilitate direct cloud account compromise. Review endpoint detection coverage for modular implant behaviour, as fragmented payloads are designed to evade signature-based detection.
Original advisory: Golden Chickens Resurfaces With Four New Malware Families and Modular Implants