Golden Chickens is a financially motivated cybercrime operation best known for developing and selling the More_eggs backdoor and related tooling through a malware-as-a-service model. The ecosystem has been associated with aliases including Venom Spider, Skeleton Spider, TA4557, and Storm-0538. Reporting also links Golden Chickens tooling to multiple downstream criminal customers, including FIN6 and Evilnum. The operation is distinct from those customers: it functions primarily as a supplier of intrusion tooling rather than solely as a single intrusion set. Golden Chickens malware and associated loaders have been used in phishing-driven intrusions, commonly relying on malicious attachments, archive files, and disguised shortcut files to trigger execution. Observed tradecraft includes obfuscated JavaScript loaders, abuse of native Windows utilities for execution and staging, PowerShell-based payload delivery, scheduled-task and Registry-based persistence, browser credential and cookie theft, command execution, screenshot capture, and data exfiltration. Related tooling in the ecosystem has included More_eggs, TerraLoader or TerraPreter-style loaders, TerraStealer, and other modular payloads used for follow-on access, credential theft, and post-compromise operations. Victimology is strongly tied to financially motivated targeting. Golden Chickens tooling has been used against financial-sector organizations, including payment-card environments and fintech-related targets, and has also appeared in campaigns aimed at cryptocurrency-linked entities. Associated intrusions have involved theft of browser-stored credentials, payment-card data, and other sensitive information. The actor’s role as a malware supplier to other cybercriminal groups makes its operational footprint broader than any single campaign, with customer groups adapting the tooling for initial access, persistence, credential theft, and monetization.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
55 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
36 malware families attributed to this actor across reporting.
31 additional families tracked in Mallory.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
Carberp has exploited multiple Windows vulnerabilities (CVE-2010-2743, CVE-2010-3338, CVE-2010-4398, CVE-2008-1084) and a .NET Runtime Optimization vulnerability for privilege escalation.
FIN6 ... targeted CVE-2013-3660, CVE-2011-2005, and CVE-2010-4398, all of which could allow local users to access kernel-level privileges.
FIN6 ... targeted CVE-2013-3660, CVE-2011-2005, and CVE-2010-4398, all of which could allow local users to access kernel-level privileges.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
The following analytic detects when su runs from a page-cache-corrupted binary... This activity is significant because it indicates a possible privilege escalation attempt, allowing a user to gain root access... CVE CVE-2026-31431 ... References ... copy-fail-CVE-2026-31431
1 more CVE tied to this actor tracked in Mallory.
222 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison point for GoldenEyeDog’s sophistication.
Listed as a threat actor associated with the generic installation exploitation analytic, but no campaign-specific activity is described in this reference.
Mentioned only as one of many threat actors associated with the ATT&CK technique/detection annotation for automated collection using Windows dir piped to findstr.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.