Golden Chickens Malware Crew Returns With Four New Tools
The criminal group behind a long-running 'malware-as-a-service' operation has rolled out fresh code, including a stripped-down loader and a browser password stealer.

Key points
- Researchers say the operators of the Golden Chickens malware-as-a-service platform have returned with four new malware families.
- The new tools are called TinyEgg, ChonkyChicken, a modular version of ChonkyChicken, and a modified browser credential stealer.
- Malware-as-a-service means criminals rent ready-made hacking tools to other criminals, much like renting software online.
- The group has kept operating despite years of public research exposing how its tools work.
- This is a threat-intelligence disclosure, not a confirmed breach at any named company.
The crew behind Golden Chickens is back in business. Security researchers say the group, which rents hacking tools to other criminals, has released four new pieces of malware. Malware is simply software written to do harm, and "malware-as-a-service" means the authors lease it out for a fee, the way a legitimate company might lease accounting software.
The finding was first reported by The Hacker News, drawing on fresh analysis of the group's activity.
Who are Golden Chickens?
Golden Chickens is the nickname researchers use for a criminal operation that builds hacking tools and rents them to other attackers. Its code has turned up in financial fraud and targeted intrusions for years. Public write-ups have exposed how the tools work, yet the operators keep going.
Think of it as a supplier, not a gang that carries out the burglaries itself. The customers do the breaking in. Golden Chickens sells the crowbar.
What are the four new tools?
The four new families are TinyEgg, ChonkyChicken, a modular version of ChonkyChicken, and a modified tool that steals passwords saved in web browsers. Each plays a different role in an attack.
| Tool | What it appears to do |
|---|---|
| TinyEgg | A small loader, meaning code that quietly pulls in more malware once it lands on a machine |
| ChonkyChicken | A larger implant that gives attackers a foothold inside a computer |
| ChonkyChicken (modular) | The same implant broken into swappable parts, so operators can add features on demand |
| Browser credential stealer | A modified tool that scrapes usernames and passwords saved in browsers like Chrome or Edge |
A "modular" build matters because it lets the criminals mix and match features without rewriting the whole program. That makes the malware harder for antivirus tools to spot, and easier for the operators to update.
Why does this matter to ordinary people?
Most readers will never see the name Golden Chickens in a news alert about their own bank or employer. The risk is indirect. Their tools tend to end up inside phishing campaigns, where criminals send fake emails to trick staff into opening a booby-trapped attachment or link. Once a staff member clicks, the loader runs, and the rest follows.
The browser credential stealer is the part with the most direct reach. If it runs on a work laptop, every password the user saved in Chrome or Edge, for email, banking portals, internal systems, can be lifted in seconds.
What should organisations do now?
Treat it as a nudge, not a fire drill. There is no named victim in this disclosure. The practical response is the same as for any credential-stealing malware: assume phishing is the delivery route, and shorten the distance between a click and a locked-down account.
That means multi-factor authentication on anything that touches money or customer data, so a stolen password on its own is not enough to get in. It means training staff to recognise the lure emails these tools ride in on. And it means watching for the small, quiet loaders like TinyEgg, which are designed to slip past first-line defences without making noise.
The fact that Golden Chickens is still shipping new code, years after being outed in public research, is the real headline here. Exposure alone does not shut these operations down.



