Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

Golden Chickens Unleashes New Malware

May 5, 2025
Reading Time: 2 mins read
in Alerts
Chimera Malware Outsmarts Firewalls

Golden Chickens, a financially motivated threat actor group, has released two new malware families: TerraStealerV2 and TerraLogger. These tools represent continued development by the group, which has been active since at least 2018 under the alias Venom Spider. TerraStealerV2 is designed to collect sensitive information, such as browser credentials, cryptocurrency wallet data, and browser extension details. TerraLogger, in contrast, is a standalone keylogger that records keystrokes and writes the logs to local files. Both malware families showcase the group’s efforts to diversify and refine their malware arsenal.

The malware is distributed in various formats, such as executable files (EXEs), dynamic-link libraries (DLLs), and Windows Installer packages (MSI). TerraStealerV2 specifically targets the Chrome ‘Login Data’ database to steal credentials. However, it does not bypass Chrome’s newer Application Bound Encryption (ABE) protections, indicating the malware might still be in development. The data captured by TerraStealerV2 is exfiltrated via Telegram and the domain “wetransfers[.]io.” The malware also utilizes trusted Windows utilities, like regsvr32.exe and mshta.exe, to avoid detection by security systems.

TerraLogger, while similar in distribution to TerraStealerV2, serves a different purpose by recording keystrokes.

It does not yet support data exfiltration or communication with a command-and-control server, which suggests it may either be a work-in-progress or designed to work with other tools in the Golden Chickens malware-as-a-service (MaaS) ecosystem. Despite its potential for malicious activity, TerraLogger appears to be less developed compared to TerraStealerV2.

The group’s use of this keylogger further highlights the expanding range of tools available for cybercriminal operations.

Both TerraStealerV2 and TerraLogger are still under active development, according to cybersecurity firm Recorded Future. The Golden Chickens group has historically focused on credential theft and unauthorized access operations. As new stealer malware families like Hannibal Stealer and Gremlin Stealer emerge, the Golden Chickens group’s tools continue to evolve. These developments point to an ongoing trend in the cybercriminal underworld, with increasingly sophisticated and targeted malware being used to steal sensitive information and bypass security measures.

Reference:

  • Golden Chickens Unleashes TerraStealerV2 and TerraLogger Malware Families
Tags: Cyber AlertsCyber Alerts 2025CyberattackCybersecurityMay 2025
ADVERTISEMENT

Related Posts

VexTrio TDS Uses Adtech To Spread Malware

Simple Typo Breaks AI Safety Via TokenBreak

June 13, 2025
VexTrio TDS Uses Adtech To Spread Malware

VexTrio TDS Uses Adtech To Spread Malware

June 13, 2025
VexTrio TDS Uses Adtech To Spread Malware

Old Discord Links Now Lead To Malware

June 13, 2025
SmartAttack Uses Sound To Steal PC Data

SmartAttack Uses Sound To Steal PC Data

June 13, 2025
SmartAttack Uses Sound To Steal PC Data

Coordinated Brute Force Hits Tomcat Manager

June 13, 2025
SmartAttack Uses Sound To Steal PC Data

Pentest Tool TeamFiltration Hits Entra ID

June 12, 2025

Latest Alerts

Old Discord Links Now Lead To Malware

VexTrio TDS Uses Adtech To Spread Malware

Simple Typo Breaks AI Safety Via TokenBreak

Coordinated Brute Force Hits Tomcat Manager

SmartAttack Uses Sound To Steal PC Data

Pentest Tool TeamFiltration Hits Entra ID

Subscribe to our newsletter

    Latest Incidents

    Cyberattack On Brussels Parliament Continues

    Swedish Broadcaster SVT Hit By DDoS

    Major Google Cloud Outage Disrupts Web

    AI Spam Hijacks Official US Vaccine Site

    DragonForce Ransomware Hits Philly Schools

    Erie Insurance Cyberattack Halts Operations

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial