Alert: Golden Chickens Unleash TerraStealerV2 to Harvest Browser Credentials and Crypto Wallets


# Golden Chickens Expands Malware Arsenal with New Threats

Cybersecurity researchers have identified two new malware families attributed to the threat group Golden Chickens (also known as Venom Spider): TerraStealerV2 and TerraLogger, indicating ongoing development of their criminal toolkit.

## New Malware Capabilities

TerraStealerV2 is designed to harvest sensitive data including:
– Browser credentials
– Cryptocurrency wallet information
– Browser extension data

Meanwhile, TerraLogger functions as a standalone keylogger that uses low-level keyboard hooks to record keystrokes and store logs locally.

## Distribution Methods

TerraStealerV2 is being distributed through multiple formats:
– Executable files (EXEs)
– Dynamic-link libraries (DLLs)
– Windows Installer packages (MSI)
– Shortcut (LNK) files

In all cases, the payload is delivered as an OCX file retrieved from an external domain (“wetransfers[.]io”). The malware exfiltrates stolen data to both Telegram and this domain, while leveraging trusted Windows utilities like regsvr32.exe and mshta.exe to evade detection.

## Development Status

Researchers from Recorded Future note that both tools appear to be under active development but lack the sophistication of mature Golden Chickens tools. TerraStealerV2 cannot bypass Chrome’s Application Bound Encryption protections introduced after July 2024, suggesting outdated code or ongoing development. TerraLogger lacks data exfiltration capabilities, indicating it may be in early development or designed to work alongside other Golden Chickens malware.

## Broader Threat Landscape

This development comes amid the emergence of other new stealer malware families including Hannibal Stealer, Gremlin Stealer, and Nullpoint Stealer. Additionally, researchers have discovered an updated version of StealC malware (V2.2.4) featuring streamlined C2 communication, RC4 encryption, and an integrated builder that allows threat actors to customize payload delivery based on geolocation, hardware IDs, and installed software.

Share This Article