CredentialKatz is a Windows credential-stealing tool focused on Chromium-based browsers, particularly Google Chrome and Microsoft Edge. It obtains plaintext credentials from the browser credential manager by injecting into a browser process and reading browser memory, rather than relying on DPAPI decryption. It can also parse credentials from browser-process minidumps. CredentialKatz has been used to steal browser-stored passwords and cookies, enabling both credential theft and session hijacking. China-linked Lotus Panda, also known as Billbug, has deployed CredentialKatz alongside ChromeKatz during espionage operations targeting government, telecommunications, aviation, construction, media, and logistics organizations in Southeast Asia.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Also deployed in the attacks are a reverse SSH tool, and two credential stealers ChromeKatz and CredentialKatz that are equipped to siphon passwords and cookies stored in the Google Chrome web browser.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named tool referenced as one of the first capable of bypassing Chrome Application-Bound Encryption to access protected browser data.
Referenced as credential-theft logic/signature pattern used as a lookalike by EDDIESTEALER to extract plaintext Chrome credentials from process memory.
Credential-extraction tooling referenced as the basis for EDDIESTEALER's Chrome-process memory scanning routine.
CredentialKatz is a credential stealer targeting Google Chrome browser data, including passwords and cookies.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.