ChromElevator is a publicly available, open-source Windows browser-data extraction tool widely incorporated into information-stealing malware and post-exploitation operations. It targets Chromium-based browsers, including Google Chrome, Microsoft Edge, and Brave, and bypasses App-Bound Encryption protections to access saved passwords, browser cookies, payment-card information, and autofill data. It can decrypt protected browser data in user mode without requiring administrator privileges. Its browser-access techniques include injection into suspended browser processes, enabling extraction within the browser’s trusted execution context. Stolen cookies expose authenticated sessions, while recovered passwords support further account compromise.
Attackers deploy ChromElevator as a standalone helper executable or embed it within malicious payloads. Observed deployment chains include multistage Donut-based loaders, ClickFix fake-verification lures, phishing, disguised software installers, and DLL sideloading through legitimate signed applications. It has been integrated into Stealit and Arkanix Stealer and delivered as a secondary native payload by NYX. Associated operations exfiltrate extracted browser data through attacker-controlled infrastructure and public communication or file-transfer services.
ChromElevator has also been used by the Iran-linked espionage group MuddyWater, also known as Seedworm, and by threat cluster UAC-0247. MuddyWater deployed it in intrusions affecting manufacturing, government, financial services, education, and aviation organizations. UAC-0247 used it for browser credential theft during operations targeting Ukrainian local government, municipal healthcare institutions, and defense personnel. Its public availability and adoption across unrelated operations make it a shared tool rather than an attribution-specific malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The campaign also deployed ChromElevator, a publicly available tool capable of extracting passwords, browser cookies and payment information from Chromium-based browsers by bypassing Google’s App-Bound Encryption protections.
Both malicious files carried ChromElevator, a tool capable of stealing passwords, cookies, and payment data from web browsers.
Stage 2: The Native Stealer While the Node.js RAT handles interactive operations, NYX downloads a second payload: chromelevator.exe, a 1.4 MB PE64 C/C++ binary hosted at hxxp://amoboobs[.]com/arquivos/chromelevator.exe.
Attackers used CHROMELEVATOR to pull authentication data and other stored credentials from internet browsers...
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The report details how the group targeted organisations across manufacturing, aviation, financial services, education, professional services and the public sector during the first quarter of 2026... designed to steal credentials, intellectual property and sensitive organisational data while remaining hidden inside victim networks for extended periods.
The report details how the group targeted organisations across manufacturing, aviation, financial services, education, professional services and the public sector during the first quarter of 2026... designed to steal credentials, intellectual property and sensitive organisational data while remaining hidden inside victim networks for extended periods.
the campaign instead injected shellcode directly into the process thread.
The second stage creates a new, suspended instance of DllHost process. It then injects the decrypted third-stage payload into this process using user-mode Asynchronous Procedure Call (APC) injection
The report details how the group targeted organisations across manufacturing, aviation, financial services, education, professional services and the public sector during the first quarter of 2026... designed to steal credentials, intellectual property and sensitive organisational data while remaining hidden inside victim networks for extended periods.
"...implant embedded within the resources of the C++ implementation... stealer extracts the payload to a temporary folder... and executes it"
the campaign instead injected shellcode directly into the process thread.
The second stage creates a new, suspended instance of DllHost process. It then injects the decrypted third-stage payload into this process using user-mode Asynchronous Procedure Call (APC) injection
The report details how the group targeted organisations across manufacturing, aviation, financial services, education, professional services and the public sector during the first quarter of 2026... designed to steal credentials, intellectual property and sensitive organisational data while remaining hidden inside victim networks for extended periods.
Unlike traditional malware campaigns, MuddyWater relied heavily on legitimate software to disguise its activity.
The malware steals browser cookies, saved passwords, financial data, and session tokens, then uses them to access accounts already signed in on the compromised computer.
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Public tooling referenced as a comparison for CrocoRat's apparent browser-process injection and named-pipe coordination intended to bypass browser secret protections. The report does not establish that CrocoRat directly incorporates ChromElevator; the shared marker is not unique lineage evidence and may occur in other tools.
A browser credential theft tool intended to target Chrome App-Bound Encryption for post-exploitation harvesting, but only mentioned as a failed download attempt from GitHub.
A publicly available browser-stealing tool used to extract passwords, cookies, and payment information from Chromium-based browsers by bypassing App-Bound Encryption protections.
Browser credential theft tool used to steal passwords, cookies, and payment data from web browsers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.