ChromElevator is a publicly available post-exploitation browser data theft tool used to extract sensitive information from Chromium-based browsers on Windows. It is designed to bypass Google Chrome’s App-Bound Encryption protections and has been observed stealing saved passwords, browser cookies, login data, payment card information, and related web data from Chrome-derived browsers. Multiple reports describe it as injecting into suspended or target browser processes to decrypt browser master keys and access protected credential stores without requiring administrative privileges in some deployments.
ChromElevator is commonly used as a secondary payload or embedded component within broader intrusion chains rather than as a standalone initial-access malware family. It has been delivered through DLL sideloading chains, downloaded by Node.js- or PowerShell-driven loaders, bundled inside infostealers, and used after compromise for credential harvesting. Observed campaigns have paired it with signed-binary abuse, process injection, and covert exfiltration workflows.
The tool has been used by a range of threat actors and malware operations, including espionage activity attributed to MuddyWater/Seedworm, intrusions tracked by CERT-UA as UAC-0247, and commodity cybercrime ecosystems involving stealers such as Arkanix Stealer and Stealit. It has also appeared in campaigns using fake software lures, phishing-driven delivery chains, ClickFix-style social engineering, and trojanized packages. Its role across these operations is consistent: harvesting browser-resident authentication material and financial data from Chromium-based browsers to support account compromise, session theft, follow-on intrusion activity, or monetization.
Because ChromElevator is an open-source and reusable capability rather than a uniquely actor-bound implant, its presence is best understood as a credential- and session-theft module frequently incorporated into larger malware frameworks and post-compromise toolsets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The campaign also deployed ChromElevator, a publicly available tool capable of extracting passwords, browser cookies and payment information from Chromium-based browsers by bypassing Google’s App-Bound Encryption protections.
Both malicious files carried ChromElevator, a tool capable of stealing passwords, cookies, and payment data from web browsers.
Stage 2: The Native Stealer While the Node.js RAT handles interactive operations, NYX downloads a second payload: chromelevator.exe, a 1.4 MB PE64 C/C++ binary hosted at hxxp://amoboobs[.]com/arquivos/chromelevator.exe.
Attackers used CHROMELEVATOR to pull authentication data and other stored credentials from internet browsers...
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The report details how the group targeted organisations across manufacturing, aviation, financial services, education, professional services and the public sector during the first quarter of 2026... designed to steal credentials, intellectual property and sensitive organisational data while remaining hidden inside victim networks for extended periods.
The report details how the group targeted organisations across manufacturing, aviation, financial services, education, professional services and the public sector during the first quarter of 2026... designed to steal credentials, intellectual property and sensitive organisational data while remaining hidden inside victim networks for extended periods.
"...spawns a suspended target browser process, and injects the decrypted code into it via Nt syscalls."
The report details how the group targeted organisations across manufacturing, aviation, financial services, education, professional services and the public sector during the first quarter of 2026... designed to steal credentials, intellectual property and sensitive organisational data while remaining hidden inside victim networks for extended periods.
"...implant embedded within the resources of the C++ implementation... stealer extracts the payload to a temporary folder... and executes it"
"...spawns a suspended target browser process, and injects the decrypted code into it via Nt syscalls."
The report details how the group targeted organisations across manufacturing, aviation, financial services, education, professional services and the public sector during the first quarter of 2026... designed to steal credentials, intellectual property and sensitive organisational data while remaining hidden inside victim networks for extended periods.
The campaign also deployed ChromElevator, a publicly available tool capable of extracting passwords, browser cookies and payment information from Chromium-based browsers by bypassing Google’s App-Bound Encryption protections.
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A browser credential theft tool intended to target Chrome App-Bound Encryption for post-exploitation harvesting, but only mentioned as a failed download attempt from GitHub.
A publicly available browser-stealing tool used to extract passwords, cookies, and payment information from Chromium-based browsers by bypassing App-Bound Encryption protections.
Browser credential theft tool used to steal passwords, cookies, and payment data from web browsers.
An open-source browser data theft tool used to steal passwords, cookies, and payment card data from Chromium-based browsers while bypassing App-Bound Encryption protections.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.