CDumper is a browser data-stealing malware component used by the Iranian state-linked threat group OilRig during the Juicy Mix campaign. It is designed specifically to target Google Chrome and harvest browser-resident data, including saved credentials, cookies, and browsing history. Its role in the intrusion set aligns with credential access and browser information collection, enabling follow-on account compromise and victim profiling.
Within Juicy Mix, CDumper operated alongside a parallel Edge-focused component known as EDumper and supported broader OilRig post-compromise activity that also included credential theft from Windows Credential Manager, local staging of stolen data, and delivery and persistence of the Mango backdoor through script-based tooling. The malware was used after access had already been established, making it part of OilRig’s collection and post-exploitation toolkit rather than an initial access mechanism.
CDumper targets Windows environments where Google Chrome is present. Reported behavior includes identifying systems or users with Chrome installed and extracting browser artifacts of operational value to the operator. The malware is associated with espionage-oriented activity attributed to OilRig and reflects the group’s recurring use of custom tooling to collect credentials and user activity data from enterprise victims.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During Juicy Mix, OilRig used the CDumper (Chrome browser) and EDumper (Edge browser) to collect credentials.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential collection tool used to dump credentials from Chrome.
Browser data stealer focused on Google Chrome; used to collect cookies, browsing history, and credentials, and to stage stolen data locally (e.g., files named Cupdate in %TEMP%).
Browser credential dumping tool used to collect credentials from Google Chrome.
Browser credential dumping tool targeting Google Chrome credentials.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.