Threat Advisory

Golden Chickens Deploy Updated Credential-Stealing Malware

Threat: Malware
Threat Actor Name: Venom Spider
Threat Actor Type: State-Sponsored
Targeted Region: Global
Alias: Golden Chickens
Threat Actor Region: Russia
Targeted Sector: Technology & IT, Finance & Banking
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A financially motivated threat actor operating a Malware-as-a-Service (MaaS) platform has developed two new malware families: TerraStealerV2 and TerraLogger. These tools are designed for credential theft and keylogging, respectively, and are linked to a known cybercriminal ecosystem used by high-profile threat groups. The malware exhibits signs of ongoing development, with TerraStealerV2 focusing on stealing browser data and cryptocurrency wallets, while TerraLogger captures keystrokes without exfiltrating them. Both tools lack the sophistication typically seen in mature malware from this actor, suggesting they are either in early stages or being refined for future campaigns.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A financially motivated threat actor operating a Malware-as-a-Service (MaaS) platform has developed two new malware families: TerraStealerV2 and TerraLogger. These tools are designed for credential theft and keylogging, respectively, and are linked to a known cybercriminal ecosystem used by high-profile threat groups. The malware exhibits signs of ongoing development, with TerraStealerV2 focusing on stealing browser data and cryptocurrency wallets, while TerraLogger captures keystrokes without exfiltrating them. Both tools lack the sophistication typically seen in mature malware from this actor, suggesting they are either in early stages or being refined for future campaigns.[emaillocker id="1283"]

 

TerraStealerV2 extracts credentials from Chrome’s "Login Data" database but fails to bypass modern encryption protections, indicating outdated or incomplete development. It exfiltrates stolen data to Telegram and a domain (wetransfersio) and is distributed via multiple file formats, including LNK and MSI files. The malware abuses legitimate Windows utilities like regsvr32exe to evade detection. In contrast, TerraLogger operates as a standalone keylogger, recording keystrokes to local files without sending data to a remote server. It uses a common keyboard-hooking technique and stores logs in plaintext, with minor updates observed in recent samples. The lack of exfiltration mechanisms suggests it may be part of a larger modular framework.

 

The discovery of these malware families highlights the continuous evolution of tools used by cybercriminal networks. While TerraStealerV2 and TerraLogger currently lack advanced stealth or persistence mechanisms, their development aligns with the threat actor’s history of refining malware for credential theft and surveillance. The use of multiple distribution methods and evasion techniques indicates a deliberate effort to maximize infection rates. As these tools mature, they may incorporate more sophisticated features, increasing their effectiveness in future campaigns. Organizations should remain vigilant for related activity, particularly phishing attempts delivering these payloads.

THREAT PROFILE:

Tactics Technique ID Technique
Initial Access T1566 Phishing
Execution T1059 Command and Scripting Interpreter
T1204 User Execution
Persistence T1547 Boot or Logon Autostart Execution
Defense Evasion T1218 System Binary Proxy Execution
T1027 Obfuscated Files or Information
Credential Access T1555 Credentials from Password Stores
Discovery T1083 File and Directory Discovery
Collection T1056 Input Capture
T1113 Screen Capture
Command and Control T1071 Application Layer Protocol
Exfiltration T1041 Exfiltration Over C2 Channel
Impact T1486 Data Encrypted for Impact

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu