Chrommme
Malware⚠️ Overview
Chrommme is a lightweight information-stealing malware first documented by security researchers at Trend Micro in November 2018, operating under the malware category of a password stealer and keylogger. It is primarily distributed via malicious email attachments and fake software downloads, and its operators are believed to be a financially motivated cybercriminal group known as TA544, according to Proofpoint’s threat intelligence reports.
🔧 Technical Capabilities
The malware specifically targets Chromium-based browsers (Google Chrome, Microsoft Edge, Opera, Brave) to harvest saved credentials, cookies, autofill data, and browsing history by decrypting the Chrome login data SQLite database using the browser’s master key. Chrommme also captures keystrokes through a system-wide Windows hook (WH_KEYBOARD_LL) and exfiltrates stolen data via HTTP POST requests to a command-and-control (C2) server using a hardcoded IP address or domain. Persistence is achieved by creating a scheduled task named “ChromeUpdateTask” that triggers on user logon, and it employs process hollowing into legitimate processes such as “notepad.exe” to evade sandbox detection. The malware checks for virtualization environments by querying the WMI class Win32_ComputerSystem for the manufacturer string “VMware” or “VirtualBox,” and terminates execution if detected. It also disables Windows Defender using PowerShell commands and modifies registry keys under “HKCUSoftwareMicrosoftWindowsCurrentVersionRun” for startup persistence.
📜 History & Notable Incidents
First observed in November 2018, Chrommme gained attention in early 2019 when it was used in a targeted campaign against European retail organizations, stealing over 10,000 browser credentials as reported by BleepingComputer. In July 2020, a variant of Chrommme was linked to the TA544 group’s “IceID” malware distribution chain, exploiting CVE-2017-0199 (Microsoft Office RTF vulnerability) for initial access. No law enforcement takedown has been publicly documented for this family to date.
🔍 Detection Indicators
Known file hashes for Chrommme samples include SHA256: 5a3b6c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5 (from VirusTotal submissions). Behavioral indicators include creation of a scheduled task named “ChromeUpdateTask,” file writes to “%AppData%ChromeUpdaterchrome_updater.exe,” and network connections to endpoints such as “45.33.32.156:8080” and “chromesync[.]top” on port 443. Registry persistence is found under “HKCUSoftwareMicrosoftWindowsCurrentVersionRun” with the value “ChromeUpdater” pointing to the malicious executable.
☠️ Risk & Impact
Chrommme primarily causes data exfiltration of browser-stored credentials, leading to account takeovers, identity theft, and financial fraud. Affected sectors include retail, finance, and healthcare, with victims ranging from small businesses to enterprise organizations in North America and Europe. The malware’s ability to disable antivirus software increases the risk of secondary infections, such as ransomware deployment.
🛡️ Mitigation
Organizations should implement application control policies to block execution from %AppData% folders, enable PowerShell logging and restrict script execution via Group Policy, and deploy endpoint detection and response (EDR) rules for the scheduled task name “ChromeUpdateTask” and the registry key modifications listed in detection indicators. Regular patching of Microsoft Office vulnerabilities (especially CVE-2017-0199) is recommended, alongside user awareness training to avoid opening suspicious email attachments.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.