ClickFix Lures Push Golden Chickens Malware

The Hacker News · High sophistication
Last updated July 30, 2026

Recorded Future reports the Golden Chickens (TAG-195) malware-as-a-service operation has resurfaced with four new malware families, including TinyEgg and ChonkyChicken. The group (and a linked operator TAG-127) has used ClickFix-style social engineering that tricks people into manually running malicious commands, leading to malware installation and credential theft from web browsers.

How the ClickFix Attack Works

Recorded Future reports that the Golden Chickens malware-as-a-service operation, tracked as TAG-195, has resurfaced with four new malware families: TinyEgg, ChonkyChicken, a modular ChonkyChicken variant, and ChromEggscalator. A linked operator, TAG-127, has been observed delivering TinyEgg through ClickFix-style social engineering, a technique that tricks users into manually executing malicious commands rather than relying on a traditional malicious attachment or link.

The lure typically appears as a generic help page or fix guide that tells the user to copy and run a command in a terminal or Run prompt to resolve an issue. When the victim complies, the attack chain downloads an OCX payload from attacker-controlled staging infrastructure, resulting in the installation of TinyEgg on the system.

Why This Approach Succeeds

ClickFix lures work because they shift the malicious action onto the user rather than automating it through a script or exploit. Because the victim is the one typing and executing the command, many technical controls that would otherwise flag automated payload delivery are bypassed. The pretext also avoids naming a specific brand, making it broadly applicable across many types of fake fix pages, which increases its reach across Windows and macOS users alike.

What Happens After Initial Access

Once TinyEgg is installed, follow-on payloads escalate the impact quickly. ChonkyChicken is described as a fully featured implant that expands on TinyEgg with browser credential theft and can even control a live browser session using the Chrome DevTools Protocol. A modular version of ChonkyChicken can load up to 14 capability modules on demand, including keylogging, screen capture, clipboard capture, network reconnaissance, and persistence management. ChromEggscalator is noted as a successor to a prior credential-stealing tool. This shows how quickly access gained through a single copy-pasted command can turn into full credential and session compromise.

Building Resistance to ClickFix Lures

  • Train staff to never copy, paste, and run commands presented by pop-ups or “fix” pages, and to confirm any such request with IT through a trusted, separate channel.
  • Educate users to be suspicious of any instructions that trigger unexpected downloads, including unusual file or component types such as OCX files.
  • Reinforce that credential theft can follow quickly after initial access, particularly from browsers and saved sessions, so quick reporting of suspicious activity matters.
  • Extend awareness training to all employees, IT helpdesk staff, and anyone with access to business-critical web applications, since browser users are a primary target of this technique.

This attack pattern maps to techniques such as user execution of malicious instructions (T1204.001) and gathering victim information to shape the lure (T1598).

Key findings

  • Recorded Future tracks Golden Chickens as TAG-195 and reports four new malware families: TinyEgg, ChonkyChicken, a modular ChonkyChicken variant, and ChromEggscalator.
  • TAG-127 has been observed delivering TinyEgg using ClickFix-style social engineering that convinces users to run attacker-provided commands.
  • Attack chains described include ClickFix lures that result in OCX payloads being downloaded from attacker-controlled infrastructure and installing TinyEgg.
  • ChonkyChicken adds browser credential theft and even live browser session control using Chrome DevTools Protocol (CDP).
  • The modular ChonkyChicken variant can load 14 capability modules on demand (e.g., keylogging, screen capture, clipboard capture, network recon, persistence management).

Who’s being targeted

  • Commonly targeted roles: All employees, IT helpdesk, Security awareness trainees, Users with access to business-critical web apps (browser users).
  • Attack channels: website.
  • Impersonated: A generic help page / fix guide (no specific brand named).

Red flags to watch for

  • Any page/instructions telling you to copy-paste and run commands to ‘fix’ something
  • Unusual file types/payloads being downloaded as part of the ‘fix’ (e.g., OCX components)
  • No verification through official IT channels before executing steps
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is Golden Chickens malware-as-a-service?

Golden Chickens, tracked as TAG-195, is a malware-as-a-service operation that Recorded Future reports has resurfaced with four new malware families, including TinyEgg and ChonkyChicken.

How does the ClickFix technique trick users?

ClickFix-style lures present a fake fix page or instructions that tell a user to copy and run a command in a terminal or Run prompt, which downloads a payload and installs malware such as TinyEgg.

What can ChonkyChicken do once installed?

ChonkyChicken expands on TinyEgg with browser credential theft and can even control a live browser session using the Chrome DevTools Protocol, and a modular variant can load 14 additional capability modules like keylogging and screen capture.

What red flags should employees watch for?

Watch for any page or pop-up asking you to copy and paste a command to fix an issue, unusual file downloads like OCX components, and instructions that skip verification through official IT channels.

Read the video transcript

If a web page ever says, "Fix required: copy and run this command", stop. That’s the ClickFix trap. Groups like Golden Chickens, TAG-195, use this to push malware like TinyEgg and ChonkyChicken. You copy the command, it quietly downloads an OCX file from their server and installs TinyEgg. From there, ChonkyChicken can grab your saved browser passwords and even ride your live Chrome sessions using DevTools, plus modules for keylogging and screen capture. Aha rule: if any web page tells you to copy‑paste a command to fix something, don’t run it, send a screenshot to IT and ask first.

Similar attacks