VoidStealer Bypasses Chrome Protection to Steal User Data
ID: 973fac3a-0eaf-5b6b-b048-1d2de4d5f720
STIX ID: report--973fac3a-0eaf-5b6b-b048-1d2de4d5f720
Feed Name: Cyber Press
VoidStealer, a Malware-as-a-Service infostealer, implements a debugger-based bypass of Google Chrome's App-Bound Encryption (ABE) to extract the v20_master_key during browser startup and silently steal session cookies, saved passwords, and payment data. The report outlines the attack chain—spawning a hidden suspended Chrome/Edge process, attaching via DebugActiveProcess, scanning chrome.dll/msedge.dll for the ABE-related plaintext marker, setting hardware breakpoints (DR0/DR7) across threads, and reading the key from registers via ReadProcessMemory—notes reuse of open-source tooling, warns of rapid MaaS-driven distribution across Chromium browsers, and recommends monitoring debugger attachments, hidden browser launches, and unauthorized ReadProcessMemory calls alongside user hygiene and patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
