logo

New ‘Sryxen’ Stealer Bypasses Chrome Encryption via Headless Browser Technique

ID: 99ab7704-711e-5bf8-854f-ce70c82db006

STIX ID: report--99ab7704-711e-5bf8-854f-ce70c82db006

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-12-04

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Sryxen is a newly observed C++ Windows information stealer sold as Malware-as-a-Service that targets Chrome 127+ by launching Chrome in headless mode and using the DevTools Protocol to retrieve decrypted cookies (bypassing App‑Bound Encryption). The stealer uses vectored exception handling to keep its payload encrypted at rest, implements multiple anti‑debug checks, avoids persistence (smash‑and‑grab), harvests credentials and crypto wallet data, compresses the data, and exfiltrates it to an attacker‑controlled Telegram bot.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.