Skip to main content
Mallory
MalwareUsed by 1 actor

CDumper

CDumper is a browser data-stealing malware used by the OilRig threat actor during the Juicy Mix campaign. It is the Google Chrome-focused counterpart to EDumper, which targeted Microsoft Edge. High-confidence reporting in the provided content states that CDumper was used to collect cookies, browsing history, and credentials from Chrome, including credentials stored in web browsers. During Juicy Mix, OilRig used CDumper and EDumper as dedicated browser dumpers/data stealers, and staged stolen browser data locally in the %TEMP% directory; associated staged filenames mentioned in the campaign include Cupdate, Eupdate, and IUpdate. The malware is associated with OilRig’s broader Juicy Mix activity, which also involved VBS and PowerShell scripts, Mango backdoor delivery and persistence, and use of compromised infrastructure including an Israeli job portal as C2. The content does not provide specific infection vectors or standalone IOCs for CDumper beyond its role and staging behavior within the campaign.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
OilRig

OilRig used the CDumper (Chrome browser) ... to collect credentials.

via mitre attackattack.mitre.org
MITRE ATT&CK

Techniques & procedures

2 distinct techniques documented for this family, organized by ATT&CK tactic.

T1555.003Credentials from Web BrowsersEvidence2

"Agent Tesla can gather credentials from a number of browsers." / "...custom-developed malware, which collected passwords from the Firefox browser storage." / "...used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores."

Discovery

1 technique
T1217Browser Information DiscoveryEvidence1
TacticDiscovery

“...leveraged ICONICSTEALER to steal browser information to include browser history...” / “...collected browser bookmark information...” / “...retrieve browser history...” / “...gather browser data such as bookmarks and visited sites...”

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping2

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.