Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Upgrades MaaS Ecosystem with Modular Tools

0
Medium
Published: 07/23/2026 (07/23/2026, 16:30:34 UTC)
Source: AlienVault OTX General

Description

TAG-195, a financially motivated malware-as-a-service developer, has evolved its ecosystem with four new modular malware families: TinyEgg, ChonkyChicken, a modular ChonkyChicken variant, and ChromEggscalator. These malware families feature WebSocket-based command-and-control, persistence via Run keys, string obfuscation, and execution through legitimate Windows binaries. TinyEgg serves as a lightweight initial-access backdoor, while ChonkyChicken adds browser credential theft and session automation. The modular architecture reduces detection risk and allows selective capability deployment. TAG-127 has deployed TinyEgg using fake security verification pages in ClickFix campaigns. This shift represents a move toward operator-driven tooling within the TAG-195 MaaS ecosystem.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/23/2026, 23:56:10 UTC

Technical Analysis

The TAG-195 threat actor group has introduced four new malware families as part of its malware-as-a-service (MaaS) ecosystem, including TinyEgg (an initial-access backdoor), ChonkyChicken (with browser credential theft and session automation), a modularized variant of ChonkyChicken using a controller-and-plugin model, and ChromEggscalator (a Chrome encryption-bypass tool). These malware families share architectural features such as WebSocket command-and-control channels, persistence via Windows Run keys, string obfuscation, and execution through legitimate Windows binaries to evade detection. TAG-127, a related actor, has been observed deploying TinyEgg through ClickFix campaigns that use fake security verification pages. The modular design enables operators to selectively provision capabilities, reducing static detection exposure and enhancing operational flexibility within the TAG-195 MaaS ecosystem.

Potential Impact

The malware families enable initial access, credential theft, session automation, and encryption bypass, facilitating unauthorized access and potential data compromise. The modular architecture increases evasion capabilities and operational flexibility, complicating detection and response efforts. Deployment via social engineering campaigns (e.g., fake security verification pages) increases the likelihood of successful infection. However, there are no known exploits in the wild reported at this time.

Mitigation Recommendations

No official patches or fixes are available as this is malware rather than a software vulnerability. Defenders should focus on detection and prevention measures tailored to the described behaviors, such as monitoring for WebSocket C2 traffic, suspicious persistence mechanisms (Run keys), and execution of legitimate Windows binaries in unusual contexts. Awareness of social engineering campaigns like ClickFix with fake security verification pages is important. Since this is a MaaS ecosystem with modular tools, continuous monitoring for new variants and updated detection signatures is recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.recordedfuture.com/research/tag-195-evolves-maas-ecosystem","https://www.recordedfuture.com/research/media_108cee2fcb0c1792cbb340558328d069bb0036624.gif?width=1200&format=pjpg&optimize=medium"]
Adversary
TAG-195
Pulse Id
6a6241aa476b940a0df81e20
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash6c23b7723a9f69ea48f02c8fe13fd60ecbfc2fb28e32e481c46ec968a66c66cd
hashb7b322f4638ead5c39031ffc7ca8c791c8d47211b09449f7ceb49f0c32a19b45
hash45c8cbaeb5c7708e7b8030e701747c65203958e82eddc41f39e0ca93bd36c114
hashd2e1ab10d5a0c16a724aeda8acb46b38f551ade58137969c3bc3c9cdc0a12425
hash5cae5202ddcc29f19f954d81ba138f11b8a4080d05fef63c05a00b9242c06967
hash9a2d714ddd5c48722c35df8a70e97f12d46bcde05dc79b7242a7e692bd346826
hash6c7619c34497f430c4f7618cfefe07d1defacfae48f6730c20f52e7a7344faa9
hash41aa04782e436345ef45dc159321d5c0e0e5cba300e55a4d1d3194e5c7c5fd97
hashd5dea9a51b984be9d7fa76e3e8ff89cfb97c335927331e8e348b9ee269070c1b
hash16735cb80d796865b2430aa11d21a539fcb00b027932f2c63e4b5c098d26585b
hashe3153ced59bb0376186b0eee0ec68f0b5aa9ae5820ef8508ae4e67625e1a3581
hash6922b319dc96d020738bcf466c4d6d9233e4767b68592e1fd9258a232f166ce1
hash03713176e7f0d9f3b37ac6eb644d90bb
hash210f57e3b1c88447ddc11467f7b2fbb9
hash2cc1ec080f7e1fcd2c0c6ae033b988c5
hash2cf627a0a9d64db3e4cd13fda3ce5636
hash3418b6439309250feb2cd983aa00da44
hash396d4f44e429e7128af9c02e0c1bdf99
hash552d991cccd6c5053dfda46c0ac32623
hash60992cdeb88dddfb17e12573e4436c42
hash70983540817fd9ff46204001a7b35ba0
hash7a0edeb5bebc51de8ce455f38d9a7670
hash7c6e4a085b1fd9b98407ba4400f91201
hash8ea54a900bd13ff3ecca01e62428e508
hash960688e3484eb744cdbbee55a7415bd1
hash9bd6f7a308418a2b376e731d9e80bac1
hash9d6f7697c0fbea55d6bfb39642eb87df
hashc21f69bbf1f78ebf4f1aa784cee035ce
hashcbe0daeec71e47840672d930e112d467
hashe4ee5ed330eaa0602f4f637f5567d08e
hashf23cb60ab395cc6bf931eed16b801ed7
hash06eade11e16465edef89ba0199d7d6f8c18a3200
hash10f6effed5a4dfff9b6e94ea90bc2134510f770f
hash26545d3db9802c44145e289b8e989d0a68bf90cb
hash2b57771989fc059bbef8f28fc0ca24eeae7e7863
hash39b3b4bb7a1b45cc155e0f8a7149df393e98b2b6
hash3a0257f31f8db0bf5e1526f4c65f79808e4a5eea
hash3ea1ccbd98c3fa8ed5cc23642ef5db39e900d88b
hash49d8bcb15cbf235a1a5f5d81a5ed4e1045b2d90a
hash5c50a13f91b0c5a109c96628e2e35f86a2c3d6c3
hash6a29c8ebd0c77e5655c39963df9c86ca9c145d08
hash72e488857a6c6c659c0c673f0e4c32a610ea41ee
hash7df85059c75bcd3e6280b4c60e1d75c094429664
hash813cd8a638b4d5cde58bdf8df7c02260a404802c
hashb5b0993b33d65f14a357b4f371d2093238c0e9d0
hashc5d8601c7b65a584696fe63e8817b395414bc1ed
hashc6c299162eae50a1d76ee9f6d42f60cef464fa04
hashd48d1a4dfb6d015df1ee019ea70ec59137c4b948
hashd810f563443e8f11478937bfcf20ff178d45eedb
hashe6b4511b53ed8ef7c857c236a5907d077862f7ad
hash086273cd91f3d6556ed2af915df310e4b184b3db84c3903aa09830d49d1fbb62
hash200fbc76bd9fab3b4adcecfe44233cf47146f5709a9735a0232cb4aa7284eadb
hash3250adbca0a0bfeab8bd88ee93b603be31fc86b341fd77a152b4843416560d53
hash337e92c233edc38842c6122fa38e0e84a478f5aa5af2a95ca6be3ca056d925b8
hash33a12c2328db22429c4a515400a57ffeaf7aec48a2a3c299ab6f1ce2d2b0e87d
hash5d585f2b24503a96011bbe928f42b1b663946e822b309f8496573c66b5ee834c
hash652346c05123b4c9556c27f5c5efc4bcd941dd66957e3797c6751246a2bff9c6
hash6adf68448b8541e3cbe4a471845cb6c2ac07613f08698567e5ed76dc2a921834
hash7ee371ff1a13a3bbd26c925a9beedb1aa0d0c03fe6f63d3803a3a55aaccd0a5b
hasha3a0aced0f3c13b0b9890ec74802a1cb4936bccfaf5e8a6a52f555c82e09d92f
hashbe7b80f42b0d859b7afaeefca04e46dc10fb5c0a532692bbbfef2924254d1175
hashc455c02ca6b3844027e05d941830de97753c3966dd57c5fa9f1938d8cd1cca3b
hashc4e2af286ee2ed12375bb66a5bff1a9d3bb5a6579842bc3a28ac00dfae195adc
hashc4e55e9e6837de01f0dadc7db299abd48630bf115a442f09ea0c6a593c559e6f
hashccb6be9211b3946d290e8b23497b8f0e6ac045d1dcde4aaae424680e9029e4eb
hashe481d16e51f90c4cc0e7096284b53eef06f7ee8b37a03d92734521d8bca24409
hashf3d2ad7440a6f985846710d2dcf0dd2db268dc690837bdf19e4e4e6684483527
hashf3f4de7eb30c01044ad3c7f2c22376d0ab6f6dc60ef6aee3cde75fd33fbddacc
hash4b8478afbfb3d4e271b47e323d893b829258a10b

Domain

ValueDescriptionCopy
domainxtrafftrck.net
domainscreenly.cam
domainahdaratlegalservices.com
domainpaysolutions.ink
domainaurekh.com
domainthessa.trackgrid.net

Threat ID: 6a62a5a29c2644c7f8e985bf

Added to database: 07/23/2026, 23:37:06 UTC

Last enriched: 07/23/2026, 23:56:10 UTC

Last updated: 07/24/2026, 02:43:17 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses