Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

Golden Chickens Unleashes New Malware

May 5, 2025
Reading Time: 2 mins read
in Alerts
Chimera Malware Outsmarts Firewalls

Golden Chickens, a financially motivated threat actor group, has released two new malware families: TerraStealerV2 and TerraLogger. These tools represent continued development by the group, which has been active since at least 2018 under the alias Venom Spider. TerraStealerV2 is designed to collect sensitive information, such as browser credentials, cryptocurrency wallet data, and browser extension details. TerraLogger, in contrast, is a standalone keylogger that records keystrokes and writes the logs to local files. Both malware families showcase the group’s efforts to diversify and refine their malware arsenal.

The malware is distributed in various formats, such as executable files (EXEs), dynamic-link libraries (DLLs), and Windows Installer packages (MSI). TerraStealerV2 specifically targets the Chrome ‘Login Data’ database to steal credentials. However, it does not bypass Chrome’s newer Application Bound Encryption (ABE) protections, indicating the malware might still be in development. The data captured by TerraStealerV2 is exfiltrated via Telegram and the domain “wetransfers[.]io.” The malware also utilizes trusted Windows utilities, like regsvr32.exe and mshta.exe, to avoid detection by security systems.

TerraLogger, while similar in distribution to TerraStealerV2, serves a different purpose by recording keystrokes.

It does not yet support data exfiltration or communication with a command-and-control server, which suggests it may either be a work-in-progress or designed to work with other tools in the Golden Chickens malware-as-a-service (MaaS) ecosystem. Despite its potential for malicious activity, TerraLogger appears to be less developed compared to TerraStealerV2.

The group’s use of this keylogger further highlights the expanding range of tools available for cybercriminal operations.

Both TerraStealerV2 and TerraLogger are still under active development, according to cybersecurity firm Recorded Future. The Golden Chickens group has historically focused on credential theft and unauthorized access operations. As new stealer malware families like Hannibal Stealer and Gremlin Stealer emerge, the Golden Chickens group’s tools continue to evolve. These developments point to an ongoing trend in the cybercriminal underworld, with increasingly sophisticated and targeted malware being used to steal sensitive information and bypass security measures.

Reference:

  • Golden Chickens Unleashes TerraStealerV2 and TerraLogger Malware Families
Tags: Cyber AlertsCyber Alerts 2025CyberattackCybersecurityMay 2025
ADVERTISEMENT

Related Posts

Apple Warns Users As CERT-FR Confirms

Former Feds Targeted By Chinese Jobs

September 12, 2025
Apple Warns Users As CERT-FR Confirms

CHILLYHELL And ZynorRAT Threaten Systems

September 12, 2025
Apple Warns Users As CERT-FR Confirms

Apple Warns Users As CERT-FR Confirms

September 12, 2025
SAP Patches Critical NetWeaver Flaw

EggStreme Malware Hits Philippine Military

September 11, 2025
SAP Patches Critical NetWeaver Flaw

RatOn Malware Hits Android Banking

September 11, 2025
SAP Patches Critical NetWeaver Flaw

SAP Patches Critical NetWeaver Flaw

September 11, 2025

Latest Alerts

Former Feds Targeted By Chinese Jobs

CHILLYHELL And ZynorRAT Threaten Systems

Apple Warns Users As CERT-FR Confirms

RatOn Malware Hits Android Banking

EggStreme Malware Hits Philippine Military

SAP Patches Critical NetWeaver Flaw

Subscribe to our newsletter

    Latest Incidents

    Panama Economy Ministry Reports Breach

    LNER Warns Customers Of Data Breach

    Hello Gym Leak Exposes Member Audio

    DDoS Defender Hit by Massive Attack

    Vienna VA Reports Data Breach Leak

    GitHub Hack Triggers Salesloft Breach

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial