OxideHarvest is a Rust-based credential-stealing malware tool associated with a Gentlemen ransomware affiliate, particularly the operator tracked as quant, and also known by the alias buildx641. It is used as part of post-compromise collection activity rather than as a core payload of the Gentlemen operators themselves. The malware is designed to harvest credentials and related data from Chromium-based and Gecko-based web browsers on compromised Windows systems. Reported targets include major Chromium-family browsers and Firefox-derived browsers, indicating broad coverage of stored browser secrets across enterprise and consumer environments.
Available reporting characterizes OxideHarvest as a credential stealer that accepts runtime parameters including connection and output options, then extracts browser-stored data for operator use. In addition to browser credential harvesting, it has been described in intrusion activity as a custom credential and data collector leveraging shadow-copy access and extraction of Active Directory credential material, including NTDS and SYSTEM hive data, indicating utility in both local credential theft and domain-focused post-exploitation. The malware has been linked to ransomware intrusion workflows in which stolen credentials support follow-on privilege escalation, lateral movement, and broader compromise objectives.
OxideHarvest is not assessed to be an in-house Gentlemen development; instead, it is attributed to an affiliate-maintained tool integrated into that ecosystem. Its observed role aligns with credential access and collection during ransomware operations targeting organizational environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Gentlemen also uses OxideHarvest, a credential stealer maintained by one of the group’s affiliates.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Additionally, ESET documented the use of OxideHarvest, a Rust-based credential-stealer tool...
Credential Access T1003.001 LSASS Memory KslDump, KslKatz, Velociraptor LSASS collection
Credential Access T1003.003 NTDS ntds.dit extraction via buildx641/OxideHarvest
ESET said it also detected a Rust-based credential stealer codenamed OxideHarvest (aka buildx641) that's capable of harvesting data from popular web browsers, including Google Chrome, Microsoft Edge, Torch, Comodo, Epic Privacy Browser, Vivaldi, Brave, Opera, OperaGX, Mozilla Firefox, Waterfox, BlackHawk, and IceCat.
ESET also found a Rust-based credential stealer called OxideHarvest, also tracked as buildx641, linked to one of the group’s affiliates. It targets Chrome, Edge, Firefox, Brave, Opera, OperaGX, Vivaldi, Waterfox, and a dozen other browsers, using supplied credentials to log into specified hosts, pull browser credentials, and write them to an output file.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Rust-based credential and data theft tool used to harvest browser data, LSASS material, and NTDS data during intrusions.
A Rust-based credential stealer tied to a specific Gentlemen affiliate rather than the core operators. It authenticates to supplied hosts using operator-provided credentials and harvests credentials from a wide range of Chromium- and Gecko-based browsers in a multithreaded loop.
A Rust-based credential stealer used by Gentlemen affiliates to harvest browser credentials from Chromium-based and Gecko-based browsers on compromised systems.
A Rust-based credential stealer linked to a Gentlemen affiliate. It targets numerous browsers, uses supplied credentials to log into specified hosts, extracts browser credentials, and writes them to an output file.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.