ClickFix Lures Push Golden Chickens Malware

The Hacker News · High sophistication
Last updated July 30, 2026

Recorded Future reports the Golden Chickens (TAG-195) malware-as-a-service operation has resurfaced with four new malware families, including TinyEgg and ChonkyChicken. The group (and a linked operator TAG-127) has used ClickFix-style social engineering that tricks people into manually running malicious commands, leading to malware installation and credential theft from web browsers.

How the ClickFix Attack Works

Recorded Future reports that the Golden Chickens malware-as-a-service operation, tracked as TAG-195, has resurfaced with four new malware families: TinyEgg, ChonkyChicken, a modular ChonkyChicken variant, and ChromEggscalator. A linked operator, TAG-127, has been observed delivering TinyEgg through ClickFix-style social engineering, a technique that tricks users into manually executing malicious commands rather than relying on a traditional malicious attachment or link.

The lure typically appears as a generic help page or fix guide that tells the user to copy and run a command in a terminal or Run prompt to resolve an issue. When the victim complies, the attack chain downloads an OCX payload from attacker-controlled staging infrastructure, resulting in the installation of TinyEgg on the system.

Why This Approach Succeeds

ClickFix lures work because they shift the malicious action onto the user rather than automating it through a script or exploit. Because the victim is the one typing and executing the command, many technical controls that would otherwise flag automated payload delivery are bypassed. The pretext also avoids naming a specific brand, making it broadly applicable across many types of fake fix pages, which increases its reach across Windows and macOS users alike.

What Happens After Initial Access

Once TinyEgg is installed, follow-on payloads escalate the impact quickly. ChonkyChicken is described as a fully featured implant that expands on TinyEgg with browser credential theft and can even control a live browser session using the Chrome DevTools Protocol. A modular version of ChonkyChicken can load up to 14 capability modules on demand, including keylogging, screen capture, clipboard capture, network reconnaissance, and persistence management. ChromEggscalator is noted as a successor to a prior credential-stealing tool. This shows how quickly access gained through a single copy-pasted command can turn into full credential and session compromise.

Building Resistance to ClickFix Lures

  • Train staff to never copy, paste, and run commands presented by pop-ups or “fix” pages, and to confirm any such request with IT through a trusted, separate channel.
  • Educate users to be suspicious of any instructions that trigger unexpected downloads, including unusual file or component types such as OCX files.
  • Reinforce that credential theft can follow quickly after initial access, particularly from browsers and saved sessions, so quick reporting of suspicious activity matters.
  • Extend awareness training to all employees, IT helpdesk staff, and anyone with access to business-critical web applications, since browser users are a primary target of this technique.

This attack pattern maps to techniques such as user execution of malicious instructions (T1204.001) and gathering victim information to shape the lure (T1598).

Key findings

  • Recorded Future tracks Golden Chickens as TAG-195 and reports four new malware families: TinyEgg, ChonkyChicken, a modular ChonkyChicken variant, and ChromEggscalator.
  • TAG-127 has been observed delivering TinyEgg using ClickFix-style social engineering that convinces users to run attacker-provided commands.
  • Attack chains described include ClickFix lures that result in OCX payloads being downloaded from attacker-controlled infrastructure and installing TinyEgg.
  • ChonkyChicken adds browser credential theft and even live browser session control using Chrome DevTools Protocol (CDP).
  • The modular ChonkyChicken variant can load 14 capability modules on demand (e.g., keylogging, screen capture, clipboard capture, network recon, persistence management).

Who’s being targeted

  • Commonly targeted roles: All employees, IT helpdesk, Security awareness trainees, Users with access to business-critical web apps (browser users).
  • Attack channels: website.
  • Impersonated: A generic help page / fix guide (no specific brand named).

Red flags to watch for

  • Any page/instructions telling you to copy-paste and run commands to ‘fix’ something
  • Unusual file types/payloads being downloaded as part of the ‘fix’ (e.g., OCX components)
  • No verification through official IT channels before executing steps
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is Golden Chickens malware-as-a-service?

Golden Chickens, tracked as TAG-195, is a malware-as-a-service operation that Recorded Future reports has resurfaced with four new malware families, including TinyEgg and ChonkyChicken.

How does the ClickFix technique trick users?

ClickFix-style lures present a fake fix page or instructions that tell a user to copy and run a command in a terminal or Run prompt, which downloads a payload and installs malware such as TinyEgg.

What can ChonkyChicken do once installed?

ChonkyChicken expands on TinyEgg with browser credential theft and can even control a live browser session using the Chrome DevTools Protocol, and a modular variant can load 14 additional capability modules like keylogging and screen capture.

What red flags should employees watch for?

Watch for any page or pop-up asking you to copy and paste a command to fix an issue, unusual file downloads like OCX components, and instructions that skip verification through official IT channels.

Read the video transcript

If a web page ever says, "Fix required: copy and run this command", stop. That’s the ClickFix trap. Groups like Golden Chickens, TAG-195, use this to push malware like TinyEgg and ChonkyChicken. You copy the command, it quietly downloads an OCX file from their server and installs TinyEgg. From there, ChonkyChicken can grab your saved browser passwords and even ride your live Chrome sessions using DevTools, plus modules for keylogging and screen capture. Aha rule: if any web page tells you to copy‑paste a command to fix something, don’t run it, send a screenshot to IT and ask first.

Similar attacks

NovaCookies Uses Real DocuSign to Steal M365 Sessions

NovaCookies Uses Real DocuSign to Steal M365 Sessions

Researchers report NovaCookies, a phishing-as-a-service toolkit that steals Microsoft 365 session cookies by proxying real logins in real time. The campaigns abuse genuine DocuSign email notifications to deliver a malicious document link that ultimately leads to an attacker-controlled Microsoft 365…

August 26, 2026
Phish Login, Then Add Your Own Google Passkey

Phish Login, Then Add Your Own Google Passkey

Researchers describe a phishing workflow where an attacker logs into a victim’s Google account using stolen password + authenticator code, then quickly enrolls a new passkey to keep access even if the password is changed. The trick relies on victims choosing a weaker sign-in fallback (one-time…

August 26, 2026
Phish Adds Passkey That Survives Reset

Phish Adds Passkey That Survives Reset

Researchers described iAuthFlow v2, a phishing toolkit that steals a live Google login session and then uses that access to enroll an attacker-controlled passkey. Because passkeys are separate login methods, the attacker can often get back into the account even after the victim changes their…

August 24, 2026
Manic Android Spyware Uses Fake Utility Apps

Manic Android Spyware Uses Fake Utility Apps

A new Android malware family called “Manic” is being used in real campaigns targeting banking, government identity, and messaging apps, especially in Ukraine and parts of Europe. It spreads through phishing sites and “dropper” apps disguised as legitimate utilities (including a booking-app lure),…

August 20, 2026
Phished npm Maintainer Led to Debug/Chalk Hijack

Phished npm Maintainer Led to Debug/Chalk Hijack

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through a lookalike npm domain. After gaining that trusted access, the attackers published malicious updates that altered crypto wallet…

July 30, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit…

July 28, 2026