ChromeStealer is a credential-theft tool used to extract stored passwords and credentials from the Google Chrome browser. The provided reporting consistently describes it as a Chrome credential extractor and a tool for extracting saved or stored passwords from Chrome. It was observed in campaigns attributed to the North Korea-linked Lazarus Group, including financially motivated intrusions associated with Medusa ransomware activity. In those operations, ChromeStealer was used alongside other Lazarus-linked and commodity tools including Comebacker, BLINDINGCAN, InfoHook, Mimikatz, RP_Proxy, and Curl. The broader campaign context included extortion and ransomware activity targeting organizations in the Middle East and the United States, including healthcare and nonprofit entities; reporting also notes U.S. mental health and autism education organizations among Medusa leak-site victims, though not all listed Medusa victims were definitively attributed to Lazarus. High-confidence functionality directly stated in the content is limited to theft of Chrome-stored credentials/passwords.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Lazarus Group's Medusa ransomware campaign includes the use of various tools - RP_Proxy, a custom proxy utility Mimikatz, a publicly available credential dumping program Comebacker, a custom backdoor exclusively used by the threat actor InfoHook, an information stealer previously identified as used in conjunction with Comebacker BLINDINGCAN (aka AIRDRY or ZetaNile), a remote access trojan ChromeStealer, a tool for extracting stored passwords from the Chrome browser.
Malware and Tools · ChromeStealer : Tool for extracting saved passwords from the Chrome browser
"Tools Used In Recent Campaigns... ChromeStealer credential tool"
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Used tools like Comebacker and Blindingcan to conduct penetration and collect credentials · Credential theft carried out using ChromeStealer and Mimikatz
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
크롬 브라우저에 저장된 비밀번호를 추출하는 정보탈취 도구다.
Credential theft tool used to extract saved passwords from the Chrome browser.
Credential/data-stealing tool referenced as used by Lazarus (details not provided in the content).
Credential theft tool used to steal passwords (notably from Chrome) during the pre-encryption phase of the intrusion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.