ChromeKatz is an open-source browser credential-theft tool used to extract passwords and session cookies directly from the process memory of Google Chrome and Microsoft Edge on Windows. It accesses sensitive data already decrypted by the browser, allowing attackers to recover plaintext cookies without decrypting their protected on-disk storage. This approach can circumvent Chromium Application-Bound Encryption protections. Cookie extraction relies on locating and traversing browser memory structures, making implementations sensitive to changes between browser versions. Stolen session cookies can enable account impersonation without possession of the victim's password.
ChromeKatz techniques have been incorporated into commodity infostealers, including STEALC and VIDAR, while EDDIESTEALER reimplements related functionality in Rust. The China-linked espionage group Lotus Panda, also known as Billbug, has deployed ChromeKatz alongside CredentialKatz and the Sagerunex backdoor. Observed campaigns included attacks against government, air traffic control, telecommunications, construction, news, and air freight organizations in Southeast Asia. ChromeKatz functions as a credential-access tool within these intrusions rather than an independently established initial-access mechanism.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Based on our analysis, the malware author appears to have reimplemented ChromeKatz within STEALC in order to bypass the app-bound encryption protection feature.
Also deployed in the attacks are a reverse SSH tool, and two credential stealers ChromeKatz and CredentialKatz that are equipped to siphon passwords and cookies stored in the Google Chrome web browser.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
STEALC calls ReadProcessMemory to access CanonicalCookieChrome structures from the Chrome network-service process. LUMMA uses NtReadVirtualMemory to locate chrome.dll and dump cookies in clear text.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A credential-theft module/tool referenced as the basis for CornFlake’s browser credential theft capability and as an on-demand extraction function in the operator panel.
A credential-theft module referenced as the basis for CornFlake’s browser credential theft capability and as a taskable extraction feature in the operator panel.
Browser credential and cookie extraction tool listed in the affiliate's GitHub activity; operational use is not established.
An open-source browser credential/cookie extraction technique/tool whose logic was reimplemented in Rust by EDDIESTEALER to bypass Chromium protections and access unencrypted sensitive browser data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.