ChromeKatz is an open-source browser credential-stealing tool focused on Google Chrome and other Chromium-based browsers. It extracts stored browser passwords and cookies, including by reading plaintext cookie material from Chromium process memory using browser-internal data structures. Stolen cookies can enable web-session hijacking, while recovered passwords support credential theft. ChromeKatz-style memory extraction has been reimplemented by multiple infostealer families to circumvent Chromium Application-Bound Encryption protections. China-linked Lotus Panda has deployed ChromeKatz alongside the CredentialKatz stealer during espionage operations against Southeast Asian organizations, including government, aviation, telecommunications, construction, media, and air-freight entities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Based on our analysis, the malware author appears to have reimplemented ChromeKatz within STEALC in order to bypass the app-bound encryption protection feature.
Also deployed in the attacks are a reverse SSH tool, and two credential stealers ChromeKatz and CredentialKatz that are equipped to siphon passwords and cookies stored in the Google Chrome web browser.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
STEALC calls ReadProcessMemory to access CanonicalCookieChrome structures from the Chrome network-service process. LUMMA uses NtReadVirtualMemory to locate chrome.dll and dump cookies in clear text.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A credential-theft module/tool referenced as the basis for CornFlake’s browser credential theft capability and as an on-demand extraction function in the operator panel.
A credential-theft module referenced as the basis for CornFlake’s browser credential theft capability and as a taskable extraction feature in the operator panel.
An open-source browser credential/cookie extraction technique/tool whose logic was reimplemented in Rust by EDDIESTEALER to bypass Chromium protections and access unencrypted sensitive browser data.
Open-source browser credential and cookie extraction tooling whose Chromium-focused logic was reimplemented by EDDIESTEALER.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.