TerraStealerV2 and TerraLogger: Golden Chickens' New Malware Families Discovered
Essential information
- Published
- 01/05/2025 20:55
- Modified
- 01/05/2025 21:28
- Tags
- 2025-05-01 browser data credential-theft keylogger malware-as-a-service revc2 stealer terraloader terralogger terrastealerv2 venomlnk
- Related entities
- 39 observables, 1 intrusion sets (apt), 11 techniques (mitre), 5 malware
Description
Insikt Group has discovered two new malware families, TerraStealerV2 and TerraLogger, linked to the financially motivated threat actor Golden Chickens. TerraStealerV2 is designed to steal browser credentials, cryptocurrency wallet data, and browser extension information, while TerraLogger functions as a standalone keylogger. These tools suggest ongoing development aimed at credential theft and keylogging. TerraStealerV2 exfiltrates data to both Telegram and a domain, while TerraLogger lacks exfiltration capabilities. Both malware families appear to be in active development, lacking the sophistication typically associated with mature Golden Chickens tooling. Organizations are advised to implement mitigation strategies to reduce the risk of compromise as these malware families evolve.