ChromElevator is an open-source post-exploitation browser data theft tool focused on Chromium-based browsers on Windows. It is designed to bypass Google Chrome’s App-Bound Encryption protections and extract sensitive browser-stored data, including saved passwords, cookies, payment card information, autofill data, and related authentication material. Multiple reports describe it as capable of decrypting browser master keys in user mode and harvesting data from browsers such as Google Chrome, Microsoft Edge, Brave, Opera, and Vivaldi, with some observed variants or deployments injecting into suspended browser processes or hooking browser renderer processes to access protected data.
ChromElevator is commonly used as a secondary payload rather than as a standalone initial-access implant. It has been embedded or dropped by a range of malware operations, including infostealer campaigns, Node.js-based malware, DLL sideloading chains, and phishing-driven intrusions. Observed delivery contexts include ClickFix lures, phishing and malvertising-driven infection chains, trojanized software, fake installers, and post-compromise deployment by espionage actors. It has been used by both cybercriminal and state-linked operations, including campaigns attributed to MuddyWater/Seedworm and activity tracked by CERT-UA as UAC-0247, as well as being incorporated into commodity stealers and MaaS offerings such as Arkanix and Stealit.
Operationally, ChromElevator functions as a credential and session theft utility. Its documented behavior includes extracting browser credentials and cookies, which can enable account compromise and session hijacking, and collecting payment-related browser data for financial fraud. In several campaigns it was paired with exfiltration mechanisms controlled by the parent malware, while some reporting also describes ChromElevator-enabled theft followed by covert exfiltration of the collected browser data. Its role is therefore best characterized as a specialized Chromium credential and browser-data stealer used during post-exploitation to monetize or operationalize access obtained through other malware stages.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The campaign also deployed ChromElevator, a publicly available tool capable of extracting passwords, browser cookies and payment information from Chromium-based browsers by bypassing Google’s App-Bound Encryption protections.
Both malicious files carried ChromElevator, a tool capable of stealing passwords, cookies, and payment data from web browsers.
Stage 2: The Native Stealer While the Node.js RAT handles interactive operations, NYX downloads a second payload: chromelevator.exe, a 1.4 MB PE64 C/C++ binary hosted at hxxp://amoboobs[.]com/arquivos/chromelevator.exe.
Attackers used CHROMELEVATOR to pull authentication data and other stored credentials from internet browsers...
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The report details how the group targeted organisations across manufacturing, aviation, financial services, education, professional services and the public sector during the first quarter of 2026... designed to steal credentials, intellectual property and sensitive organisational data while remaining hidden inside victim networks for extended periods.
The report details how the group targeted organisations across manufacturing, aviation, financial services, education, professional services and the public sector during the first quarter of 2026... designed to steal credentials, intellectual property and sensitive organisational data while remaining hidden inside victim networks for extended periods.
the campaign instead injected shellcode directly into the process thread.
The second stage creates a new, suspended instance of DllHost process. It then injects the decrypted third-stage payload into this process using user-mode Asynchronous Procedure Call (APC) injection
The report details how the group targeted organisations across manufacturing, aviation, financial services, education, professional services and the public sector during the first quarter of 2026... designed to steal credentials, intellectual property and sensitive organisational data while remaining hidden inside victim networks for extended periods.
"...implant embedded within the resources of the C++ implementation... stealer extracts the payload to a temporary folder... and executes it"
the campaign instead injected shellcode directly into the process thread.
The second stage creates a new, suspended instance of DllHost process. It then injects the decrypted third-stage payload into this process using user-mode Asynchronous Procedure Call (APC) injection
The report details how the group targeted organisations across manufacturing, aviation, financial services, education, professional services and the public sector during the first quarter of 2026... designed to steal credentials, intellectual property and sensitive organisational data while remaining hidden inside victim networks for extended periods.
Unlike traditional malware campaigns, MuddyWater relied heavily on legitimate software to disguise its activity.
The campaign also deployed ChromElevator, a publicly available tool capable of extracting passwords, browser cookies and payment information from Chromium-based browsers by bypassing Google’s App-Bound Encryption protections.
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A browser credential theft tool intended to target Chrome App-Bound Encryption for post-exploitation harvesting, but only mentioned as a failed download attempt from GitHub.
A publicly available browser-stealing tool used to extract passwords, cookies, and payment information from Chromium-based browsers by bypassing App-Bound Encryption protections.
Browser credential theft tool used to steal passwords, cookies, and payment data from web browsers.
An open-source browser data theft tool used to steal passwords, cookies, and payment card data from Chromium-based browsers while bypassing App-Bound Encryption protections.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.