logo

Vidar Malware Bypasses Chrome Encryption Using CryptUnprotectMemory

ID: 5ed0dedc-463f-523b-8fab-c4957ac5554e

STIX ID: report--5ed0dedc-463f-523b-8fab-c4957ac5554e

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2026-06-20

Date Updated: 2026-06-21

Author: Lucas Martin

...
...

**Executive Summary:** The report documents a sophisticated Vidar infostealer technique that forks Chrome processes, scans live memory to locate the Chromium Encryptor::KeyRing v20 node, and uses APC-based in-process calls to CryptUnprotectMemory to extract and validate the v20_master_key, then re-encrypts memory to cover traces; it includes detection guidance (monitor NtCreateProcessEx with null section handles and APC queuing into browser threads) and an IoC hash for the sample.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.