MKG is a Chrome data-dumping malware/tool used by the OilRig threat actor during the Outer Space campaign. The available content attributes MKG to OilRig with high confidence and describes it specifically as a Chrome data dumper used for browser information discovery. In the broader campaign context, OilRig used HTTP-based command-and-control communications, including Microsoft Exchange Web Services (EWS), VBS droppers with obfuscated strings, compromised third-party infrastructure including an Israeli human resources website as C2, Microsoft 365 accounts for C2 support, and additional implants such as the Solar backdoor. High-confidence functionality directly stated for MKG is limited to dumping or collecting Google Chrome browser data; the content does not provide more specific artifacts or file paths for MKG itself, nor explicit indicators of compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
1 distinct technique documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chrome data dumper used for browser information discovery (e.g., extracting data from Chrome).
Chrome data dumper used to extract browser data.
Chrome data dumper used to extract browser data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.