Golden Chickens, also known as Venom Spider, has once again come under the spotlight after cybersecurity researchers discovered four new malware families and updated modular implants linked to the group’s Malware-as-a-Service (MaaS) platform. The latest findings show that the group is actively improving its cyber tools to help criminals steal sensitive information and gain unauthorized access to victim systems. Researchers believe these developments highlight the group’s continued focus on expanding its malware ecosystem.

The newly identified malware families include TerraStealerV2 and TerraLogger, along with two modular implants known as RevC2 and Venom Loader. Each tool has a different purpose, allowing attackers to combine them depending on the target and the attack requirements. This modular design makes the malware more flexible and helps threat actors launch more advanced cyberattacks without relying on a single malicious program.
TerraStealerV2 is mainly designed to steal valuable information stored on infected computers. It targets saved browser passwords, cryptocurrency wallet data, browser extensions, and other sensitive credentials that could be used for financial fraud or account takeover. Researchers also found that the malware sends the stolen information to attacker-controlled infrastructure, although some of its features suggest that it is still under active development.

Another newly discovered tool, TerraLogger, works as a keylogger that silently records everything a victim types on the keyboard. The captured keystrokes are saved locally, but researchers noted that the malware currently does not include built-in data exfiltration or command-and-control capabilities. This indicates that TerraLogger may either be unfinished or designed to work alongside other Golden Chickens malware modules.
Researchers also highlighted the continued use of RevC2 and Venom Loader within the Golden Chickens toolkit. RevC2 acts as a backdoor capable of executing remote commands, stealing browser cookies and passwords, capturing screenshots, and supporting additional malicious activities. Venom Loader is responsible for loading other malware onto infected devices, allowing attackers to deploy different payloads whenever needed.

Golden Chickens usually spreads its malware through phishing campaigns that trick users into opening malicious files disguised as resumes, software installers, payment documents, or business-related content. The malware has been distributed in several file formats, including LNK shortcuts, MSI installers, DLL files, and executable programs. It also abuses trusted Windows utilities to reduce the chances of being detected by security software.
The Golden Chickens operation has been active since at least 2018 and follows a Malware-as-a-Service model, where cybercriminals can rent or purchase its tools for their own attacks. Security researchers have previously linked this malware platform to well-known cybercrime groups such as FIN6, Cobalt Group, and Evilnum. Over the years, the group has developed several malware families that support credential theft, ransomware deployment, reconnaissance, and remote access operations.

Researchers believe the latest discoveries show that Golden Chickens continues to improve and expand its malware platform despite ongoing security efforts. Although some of the newly identified tools appear to be incomplete, experts expect them to become more capable as development continues. Organizations are advised to keep systems updated, remain cautious of phishing emails, use strong endpoint protection, and monitor for unusual activity to reduce the risk of compromise from these evolving threats.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news