ChromeKatz is a browser credential theft tool focused on extracting credentials and cookies from Chromium-based browsers, and in some reporting also from Firefox-family browsers. It is designed to recover sensitive browser data both from on-disk stores and directly from browser process memory. Publicly described implementations include theft of saved passwords and live cookie extraction, including techniques intended to bypass Chromium Application-Bound Encryption on Windows and to decrypt Firefox credential material protected through NSS/SDR mechanisms. ChromeKatz methodology has also been cited as a memory-scraping approach for dumping Chromium browser memory and walking internal structures to recover plaintext cookies.
The malware is associated with credential theft operations and has appeared both as a standalone stealer component and as functionality reimplemented inside other malware families. It has been referenced in intrusions attributed to the China-linked espionage group Lotus Panda, also known as Billbug, where it was deployed alongside other tooling to siphon Chrome passwords and cookies. Separately, ChromeKatz-style techniques have been reimplemented by other infostealers, including Rust-based malware, reflecting its influence as an openly adopted browser-theft approach.
Operationally, ChromeKatz targets Windows environments because the documented theft and encryption-bypass techniques center on Chromium and Firefox browser data handling on Windows systems. Its core behavior is credential and session data theft rather than persistence or remote administration. The tool is notable for enabling theft of both stored credentials and active authenticated browser material, making it useful for account compromise, session takeover, and follow-on access to enterprise and consumer services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Also deployed in the attacks are a reverse SSH tool, and two credential stealers ChromeKatz and CredentialKatz that are equipped to siphon passwords and cookies stored in the Google Chrome web browser.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A credential-theft module/tool referenced as the basis for CornFlake’s browser credential theft capability and as an on-demand extraction function in the operator panel.
A credential-theft module referenced as the basis for CornFlake’s browser credential theft capability and as a taskable extraction feature in the operator panel.
An open-source browser credential/cookie extraction technique/tool whose logic was reimplemented in Rust by EDDIESTEALER to bypass Chromium protections and access unencrypted sensitive browser data.
ChromeKatz is a credential stealer designed to extract passwords and cookies from the Google Chrome browser.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.