ChromePass is an openly available NirSoft browser password dumping utility used to harvest stored credentials from Chromium-based browsers. The provided content identifies it as a secondary payload in the HeptaX campaign, where it was deployed after initial compromise via malicious LNK files inside ZIP archives, likely delivered through phishing. In that activity, the broader intrusion targeted the healthcare sector, established persistence, weakened security settings, enabled unauthorized RDP access, and used ChromePass specifically for credential theft from Chromium-based browsers. Reported associated sample hash for ChromePass.exe is SHA-256 4b127e7b83148bfbe56bd83e4b95b2a4fdb69e1c9fa4e0c021a3bfb7b02d8a16. The content also states that APT3 used ChromePass for credential access/collection and that Lazarus Group obtained ChromePass among tools used during Operation Dream Job. High-confidence associations in the provided material therefore link ChromePass to credential collection activity by both APT3 and Lazarus Group, as well as deployment in the HeptaX cyberespionage campaign.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
After deploying PoisonX for detection evasion, the GodDamn ransomware attacker deployed a comprehensive suite of 14 credentials-harvesting tools comprising Mimikatz and 13 NirSoft tools
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ChromePass is used to harvest stored credentials from Chromium-based browsers on compromised systems.
Tool used to recover/steal credentials (commonly Chrome browser passwords) as part of Lazarus tooling in Operation Dream Job.
Utility for extracting stored Google Chrome credentials, used to harvest passwords for account takeover and lateral movement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.