Full Report
The financially motivated Golden Chickens group, known for operating under a MaaS model, has been linked to two newly identified malicious strains, TerraStealerV2 and TerraLogger, which indicates the ongoing group’s efforts to enhance and expand its offensive toolset. TerraStealerV2 collects browser credentials, crypto wallet data, and details from browser extensions, while TerraLogger acts as a […] The post TerraStealerV2 and TerraLogger Detection: Golden Chickens Threat Actor Behind New Malware Families appeared first on SOC Prime.
Analysis Summary
# Threat Actor: Golden Chickens
## Attribution & Identity
The threat actor is identified as **Golden Chickens**. They are linked to the deployment of new malware families, specifically **TerraStealerV2** and **TerraLogger**. The group has a proven expertise in building credential theft and access tools. They are also known to be behind the deployment of the **RevC2 backdoor** and **Venom Loader**, which were previously delivered via **VenomLNK**.
## Activity Summary
The latest activity involves the deployment of the new malware families, TerraStealerV2 and TerraLogger. These tools appear to be under active development, lacking the sophisticated stealth features of more refined Golden Chickens' toolkit pieces, indicating ongoing evolution.
## Tactics, Techniques & Procedures
- Deployment of custom malware families designed for credential theft and access.
- Use of **TerraStealerV2** (a presumed stealer/information gathering tool).
- Use of **TerraLogger** (functionality not fully detailed, but associated with the group's access toolkit).
- Previous use of **RevC2 backdoor** and **Venom Loader**.
- Previous delivery mechanism included **VenomLNK**.
## Targeting
- Sectors: Not explicitly detailed, but implied sectors targeted due to the nature of their tools (credential theft, access).
- Geography: Not specified in the provided context.
- Victims: No specific organizations mentioned in the provided context.
## Tools & Infrastructure
- Malware families used: **TerraStealerV2**, **TerraLogger**, **RevC2 backdoor**, **Venom Loader**.
- Infrastructure: Delivery mechanism included **VenomLNK**. (Specific IPs/C2 domains are not listed in the context).
## Implications
Golden Chickens is an evolving threat actor, actively developing new malware strains (TerraStealerV2 and TerraLogger). Their demonstrated history with potent access tools like RevC2 suggests that these new tools are likely iterations aimed at improving their operational capabilities, particularly in credential theft. Organizations must anticipate further sophistication in their toolkit.
## Mitigations
- Implement proactive cybersecurity strategies.
- Monitor for new malware families associated with credential theft and access.
- Organizations should defend against continuously evolving threats in a timely manner.