TerraStealerV2 and TerraLogger Detection: Golden Chickens Threat Actor Behind New Malware Families
#GoldenChickens #TerraStealerV2 #TerraLogger
https://socprime.com/blog/detect-terrastealerv2-terralogger-attacks-by-golden-chickens/
TerraStealerV2 and TerraLogger Detection: Golden Chickens Threat Actor Behind New Malware Families  | SOC Prime

Detect Golden Chickens attacks leveraging TerraStealerV2 and TerraLogger malware with a set of Sigma rules in the SOC Prime Platform.

SOC Prime

⚠️ Threat alert: Golden Chickens unleashes TerraStealerV2 & TerraLogger 🤖🐔

🔥 What’s new:
🕵️‍♂️ TerraStealerV2 steals browser creds, crypto wallets & extension data
⌨️ TerraLogger logs keystrokes via OCX payloads for future exfiltration
🔄 Both are actively developed — expect rapid feature additions

🔍 Why it matters:
🚫 OCX payloads evade many AV solutions
🔐 Stolen credentials = instant account takeover
💱 Crypto wallets at risk of clean sweeps

🛠️ Action steps:
🛑 Block unsigned OCX/ActiveX modules at the endpoint
🔒 Enforce strict application whitelisting policies
📊 Deploy behavioral analytics to detect unusual loads & registry changes
🔄 Update threat intel feeds & IOC lists in SIEM/EDR tools

🛡️ Stay ahead of evolving MaaS threats by hardening your OCX defenses and continuously monitoring for stealth injection techniques.

#CyberSecurity #Malware #GoldenChickens #ThreatIntel #EndpointSecurity #OCX #MaaS #security #privacy #cloud #infosec

https://thehackernews.com/2025/05/golden-chickens-deploy-terrastealerv2.html

Golden Chickens Deploy TerraStealerV2 to Steal Browser Credentials and Crypto Wallet Data

Golden Chickens launch TerraStealerV2 and TerraLogger; both still developing but actively steal data via OCX payloads.

The Hacker News

Certains des cybercriminels russes les plus dangereux viennent de voir leur revendeur de logiciels malveillants démasqué :

https://www.forbes.com/sites/thomasbrewster/2023/05/18/rich-russian-cybercriminals-have-their-malware-dealer-unmasked/?sh=33ca472e13c2

"Jack est le fournisseur d'un logiciel malveillant appelé #GoldenChickens, utilisé par certaines des bandes de cybercriminels russes soupçonnées d'avoir causé plus d'un milliard de dollars de dommages en piratant de grandes entreprises aux États-Unis et en Europe"

"Ils espèrent que l'identification de ce trentenaire fera fuir ses clients"

Some Of Russia’s Most Dangerous Cybercriminals Just Had Their Malware Dealer Unmasked

American sleuths claim what might be a major cyber scalp by uncovering the creator of the ‘Golden Chickens’ malware that’s tied to over $1 billion in damages. They’re hopeful it will disrupt two of Russia’s most profitable hacking crews.

Forbes