Share This:

Cybersecurity Threat AdvisoryResearchers have identified a new remote access trojan (RAT) called ChonkyChicken, which threat actors use to steal browser credentials, hijack active browser sessions, and move laterally across Windows networks. Barracuda advises organizations to focus on detection, monitoring, and security hardening, as this threat does not involve a patchable software vulnerability.

What is the threat?

ChonkyChicken is a modular remote access trojan that combines credential theft, session hijacking, remote command execution, network reconnaissance, and user surveillance. Infection begins when a victim follows instructions from a fake verification page and runs a malicious command. The command downloads additional malware, including the TinyEgg backdoor, which ultimately installs ChonkyChicken.

Why is it noteworthy?

This malware goes beyond traditional credential theft by combining session hijacking, reconnaissance, persistence, and surveillance in a single framework. Researchers have linked the activity to the TAG-195 (Golden Chickens) malware-as-a-service ecosystem, which provides tools to multiple cybercriminal groups. The malware’s ability to hijack active browser sessions can allow attackers to maintain access even after a victim resets their password.

The campaign also relies on ClickFix social engineering and abuse of trusted Windows utilities, helping attackers evade detection.

What is the exposure or risk?

Organizations face increased risk when users can execute commands from the Windows Run dialog or when business-critical applications rely heavily on browser-based authentication.

Successful compromise can lead to:

  • Theft of browser credentials.
  • Hijacking of active business application sessions.
  • Persistence on compromised systems.
  • Network reconnaissance and lateral movement.
  • Ongoing surveillance of affected users.
  • Additional malware deployment and broader network compromise.

Organizations with limited monitoring, weak privilege controls, or insufficient network segmentation may face greater risk.

What are the recommendations?

Barracuda MSP recommends the following actions:

  • Restrict or closely monitor execution of commands pasted into the Windows Run dialog.
  • Provide user awareness training focused on ClickFix-style social engineering attacks.
  • Block or restrict regsvr32.exe from loading files in user-writable directories.
  • Monitor for Chrome or Edge processes launched with remote debugging enabled.
  • Monitor for unusual browser activity, WebSocket connections, and session hijacking indicators.
  • Enforce phishing-resistant MFA where possible.
  • Revoke active browser sessions, not just passwords, following a suspected compromise.
  • Limit administrative privileges and implement network segmentation to reduce lateral movement opportunities.

Barracuda recommends combining these controls with continuous monitoring and rapid response capabilities to detect, contain, and remediate related activity.

References

For more in-depth information about the recommendations, please visit the following links:

If you have any questions about this Cybersecurity Threat Advisory, don’t hesitate to get in touch with Barracuda Managed XDR’s Security Operations Center.


Share This:
Spartak Myrto

Posted by Spartak Myrto

Spartak is a Cybersecurity Analyst at Barracuda MSP. He supports our XDR service delivery and is highly skilled at analyzing security events to detect cyber threats, helping keep our partners and their customers protected.

Leave a reply

Your email address will not be published. Required fields are marked *

 

This site uses Akismet to reduce spam. Learn how your comment data is processed.