Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

Golden Chickens Unleashes New Malware

May 5, 2025
Reading Time: 2 mins read
in Alerts
Chimera Malware Outsmarts Firewalls

Golden Chickens, a financially motivated threat actor group, has released two new malware families: TerraStealerV2 and TerraLogger. These tools represent continued development by the group, which has been active since at least 2018 under the alias Venom Spider. TerraStealerV2 is designed to collect sensitive information, such as browser credentials, cryptocurrency wallet data, and browser extension details. TerraLogger, in contrast, is a standalone keylogger that records keystrokes and writes the logs to local files. Both malware families showcase the group’s efforts to diversify and refine their malware arsenal.

The malware is distributed in various formats, such as executable files (EXEs), dynamic-link libraries (DLLs), and Windows Installer packages (MSI). TerraStealerV2 specifically targets the Chrome ‘Login Data’ database to steal credentials. However, it does not bypass Chrome’s newer Application Bound Encryption (ABE) protections, indicating the malware might still be in development. The data captured by TerraStealerV2 is exfiltrated via Telegram and the domain “wetransfers[.]io.” The malware also utilizes trusted Windows utilities, like regsvr32.exe and mshta.exe, to avoid detection by security systems.

TerraLogger, while similar in distribution to TerraStealerV2, serves a different purpose by recording keystrokes.

It does not yet support data exfiltration or communication with a command-and-control server, which suggests it may either be a work-in-progress or designed to work with other tools in the Golden Chickens malware-as-a-service (MaaS) ecosystem. Despite its potential for malicious activity, TerraLogger appears to be less developed compared to TerraStealerV2.

The group’s use of this keylogger further highlights the expanding range of tools available for cybercriminal operations.

Both TerraStealerV2 and TerraLogger are still under active development, according to cybersecurity firm Recorded Future. The Golden Chickens group has historically focused on credential theft and unauthorized access operations. As new stealer malware families like Hannibal Stealer and Gremlin Stealer emerge, the Golden Chickens group’s tools continue to evolve. These developments point to an ongoing trend in the cybercriminal underworld, with increasingly sophisticated and targeted malware being used to steal sensitive information and bypass security measures.

Reference:

  • Golden Chickens Unleashes TerraStealerV2 and TerraLogger Malware Families
Tags: Cyber AlertsCyber Alerts 2025CyberattackCybersecurityMay 2025
ADVERTISEMENT

Related Posts

TikTok Videos Spread Vidar StealC Malware

TikTok Videos Spread Vidar StealC Malware

May 23, 2025
TikTok Videos Spread Vidar StealC Malware

New ZeroCrumb Malware Steals Browser Cookies

May 23, 2025
TikTok Videos Spread Vidar StealC Malware

CISA Commvault ZeroDay Flaw Risks Secrets

May 23, 2025
GitLab Patch Stops Service Disruption Risks

Function Confusion Hits Serverless Clouds

May 22, 2025
GitLab Patch Stops Service Disruption Risks

3AM Ransomware Email Bomb and Vishing Threat

May 22, 2025
GitLab Patch Stops Service Disruption Risks

GitLab Patch Stops Service Disruption Risks

May 22, 2025

Latest Alerts

New ZeroCrumb Malware Steals Browser Cookies

TikTok Videos Spread Vidar StealC Malware

CISA Commvault ZeroDay Flaw Risks Secrets

GitLab Patch Stops Service Disruption Risks

3AM Ransomware Email Bomb and Vishing Threat

Function Confusion Hits Serverless Clouds

Subscribe to our newsletter

    Latest Incidents

    Cetus Crypto Exchange Hacked For $223M

    MCP Data Breach Hits 235K NC Lab Patients

    UFCW Data Breach Risks Social Security Data

    Cyberattack Paralyzes French Hauts de Seine

    Santa Fe City Loses $324K In Hacker Scam

    Belgium Housing Hit by Ransomware Attack

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial