Badbullzvenom

Threat Actor updated a month ago (2024-11-29T13:38:28.719Z)
Download STIX
Preview STIX
Badbullzvenom, also known as Lucky and Jack, is a Romanian threat actor identified by eSentire as the second developer of the Golden Chickens malware. This malware has been utilized by prominent cybercrime operations such as the Russian Cobalt Group and FIN6. The identification was reported on May 22, 2023, and linked Badbullzvenom to the Golden Chickens toolkit, including the more_eggs component, distributed by Venom Spider, an underground Malware-as-a-Service (MaaS) provider. Additionally, Badbullzvenom has been associated with the release of a separate tool called VenomKit in 2017, which has since evolved into the Golden Chickens MaaS. The alias Badbullzvenom gained further notoriety when another threat actor named "babay" accused him of stealing $1 million on the Exploit.in forum on July 18, 2022. Babay subsequently issued a $200,000 bounty for any information leading to Badbullzvenom's real identity. Further investigations revealed that Badbullzvenom had brokered a deal with a Montreal-based cybercriminal known as 'Chuck' to use his aliases "badbullz" and "badbullzvenom" on various underground forums, essentially allowing him to start with a clean slate and build credibility under these new aliases. Interestingly, Badbullzvenom's association with the "LUCKY" account led to his unmasking. A critical mistake was made when the Jabber account was used, linking LUCKY to Badbullzvenom. eSentire characterized Jack as the true mastermind behind Golden Chickens, operating the "badbullzvenom" account on the Russian-language Exploit.in forum alongside "Chuck from Montreal." It is speculated that the cessation of posting through the LUCKY account and the subsequent release of a macro-building kit called MULTIPLIER in 2015 via the badbullzvenom account further solidified Jack's role as a key player in this cybercrime network.
Description last updated: 2024-10-01T20:16:43.043Z
What's your take? (Question 1 of 1)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Golden Chickens is a possible alias for Badbullzvenom. Golden Chickens, also known as More_eggs, is a stealthy and capable malware suite primarily used by financially-motivated cybercrime groups such as the Cobalt Group and FIN6. The malware was initially discovered in 2018 and has been primarily targeting organizations in Southeast Asia, stealing sensi
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Maas
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Badbullzvenom Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more