icon
icon
icon
icon
Upgrade
Upgrade

News /

Articles /

Golden Chickens Unleashes New Malware Tools Targeting Browsers, Crypto Wallets

Coin WorldMonday, May 5, 2025 2:16 am ET
2min read

Cybercriminal group Golden Chickens has resurfaced with a new set of malware tools designed to steal credentials, log keystrokes, and compromise user security on a large scale. The two new threats, named TerraStealerV2 malware and TerraLogger, are the latest additions to the group’s malware-as-a-service (MaaS) offerings, showcasing their ongoing efforts to evolve their cybercrime tactics.

Golden Chickens, also known as Venom Spider, has been linked to significant credential theft and infiltration campaigns in the past, most notably through its More_eggs malware. The new variants, however, indicate a strategic shift toward more aggressive targeting of browsers, crypto wallets, and user keystrokes. These malware tools are being distributed through various file formats, including EXE, msi, and LNK, making them difficult to detect and easy to spread.

TerraStealerV2 malware is engineered to extract sensitive user data from browsers and cryptocurrency wallets. It scans for browser credentials, accesses saved logins, and attempts to extract information from browser extensions, potentially leading to crypto wallet theft if the extensions are used for asset management or trading. The malware is often delivered via OCX payloads from shady domains. Once downloaded, it uses legitimate Windows utilities like regsvr32.exe and mshta.exe to execute its payload while evading security systems. Although it attempts to pull Chrome login data, it fails to bypass the newer Application Bound Encryption (ABE) protocols introduced in Chrome post-July 2024, suggesting that the tool may still be under active development or simply outdated. The data collected by TerraStealerV2 is sent to Telegram channels and external servers, providing attackers with real-time access to user credentials and activity.

Ask Aime: "Are cybercriminals targeting my browser and crypto wallet security with new malware like TerraStealerV2 and TerraLogger?"

TerraLogger, on the other hand, functions as a standalone keylogger, silently capturing every keystroke typed on the infected machine. From login credentials to personal chats, this malware can record it all. Although TerraLogger does not currently exfiltrate data or interact with any command-and-control (C2) servers, its design suggests future integration with broader malware campaigns. Golden Chickens may be planning to pair this keylogger with other tools in their ecosystem to create a more comprehensive infection chain. Despite its simplicity, TerraLogger poses a significant threat to browser security, especially when used in combination with data-exfiltration tools like TerraStealerV2.

Golden Chickens is employing a variety of file types to distribute their malware, increasing the chances of infection. Common delivery formats include executables (EXE), Microsoft Installer files (MSI), Windows Shortcut files (LNK), and OLE Control Extensions (OCX). This multi-format approach makes it more likely for unsuspecting users to install the malware. Once executed, the payloads spring into action, mining for data or logging inputs while avoiding basic antivirus scans. The use of known Windows utilities and Telegram for data transfer provides both obfuscation and control, as messages can be quickly customized or deleted on the attacker’s end.

The emergence of TerraStealerV2 signals a renewed focus on browser-based attacks. With many users storing credentials in browsers or using browser extensions to manage cryptocurrencies, a single infection could compromise access to financial platforms, crypto wallets, or even corporate intranets. The rise of crypto wallet theft through malware like TerraStealerV2 reflects a broader trend in cybercrime, where stealers are becoming more modular, customizable, and harder to detect. Even though both TerraStealerV2 and TerraLogger appear to still be under development, their current functionality is already dangerous. As Golden Chickens continues to refine these tools, we can expect even more stealth, deeper system penetration, and broader targeting capabilities.

The advent of new malware tools from Golden Chickens demonstrates how cybercriminals are developing new methodologies. Though TerraLogger is limited as purely a keylogger, it can perform some of the functions of a keylogger with the TerraStealerV2 malware or the rest of the malware toolkit as part of a greater multi-stage threat. With more reports of browser vulnerabilities and stolen crypto wallets, it is important to keep up with the ongoing availability of resources like Golden Chickens. Users and organizations should be tracking everything they download, limiting the amount of insecure software they use, and ensuring their browsers are up-to-date with the latest security protocols. The history of TerraStealerV2 and TerraLogger is just the start, and will continue to evolve, just as our responses must evolve.

Comments

Add a public comment...
Post
Refresh
Disclaimer: the above is a summary showing certain market information. AInvest is not responsible for any data errors, omissions or other information that may be displayed incorrectly as the data is derived from a third party source. Communications displaying market prices, data and other information available in this post are meant for informational purposes only and are not intended as an offer or solicitation for the purchase or sale of any security. Please do your own research when investing. All investments involve risk and the past performance of a security, or financial product does not guarantee future results or returns. Keep in mind that while diversification may help spread risk, it does not assure a profit, or protect against loss in a down market.
You Can Understand News Better with AI.
Whats the News impact on stock market?
Its impact is
fork
logo
AInvest
Aime Coplilot
Invest Smarter With AI Power.
Open App