New ‘Sryxen’ Stealer Bypasses Chrome Encryption via Headless Browser Technique
ID: 99ab7704-711e-5bf8-854f-ce70c82db006
STIX ID: report--99ab7704-711e-5bf8-854f-ce70c82db006
Feed Name: cybersecurityNews.com
Sryxen is a newly observed C++ Windows information stealer sold as Malware-as-a-Service that targets Chrome 127+ by launching Chrome in headless mode and using the DevTools Protocol to retrieve decrypted cookies (bypassing App‑Bound Encryption). The stealer uses vectored exception handling to keep its payload encrypted at rest, implements multiple anti‑debug checks, avoids persistence (smash‑and‑grab), harvests credentials and crypto wallet data, compresses the data, and exfiltrates it to an attacker‑controlled Telegram bot.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
