EDumper is a browser data-stealing malware component used by the Iranian state-linked threat group OilRig during the Juicy Mix campaign. It is designed to target Microsoft Edge and harvest browser-resident data, specifically credentials, cookies, and browsing history. Its role in the intrusion set aligns with browser credential theft and browser information collection to support follow-on account access, victim profiling, and operational awareness.
EDumper has been documented alongside a parallel Chrome-focused component, CDumper, as part of OilRig’s broader tooling in Juicy Mix. In that campaign, the malware operated within an ecosystem that also included script-based delivery and persistence mechanisms, credential theft from additional password stores, local staging of stolen data, and web-based command-and-control activity. The available evidence supports EDumper as a focused Edge data stealer rather than a general-purpose backdoor or loader.
The malware is associated with targeted espionage activity attributed to OilRig, a threat actor commonly linked to operations in the Middle East. High-confidence reporting ties EDumper to collection of browser credentials and session-relevant artifacts from Windows endpoints running Microsoft Edge.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During Juicy Mix, OilRig used the CDumper (Chrome browser) and EDumper (Edge browser) to collect credentials.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential collection tool used to dump credentials from Edge.
Browser data stealer focused on Microsoft Edge; used to collect cookies, browsing history, and credentials, and to stage stolen data locally (e.g., files named Eupdate in %TEMP%).
Browser credential dumping tool used to collect credentials from Microsoft Edge.
Browser credential dumping tool targeting Microsoft Edge credentials.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.