logo

Katz and Mouse Game: MaaS Infostealers Adapt to Patched Chrome Defenses

ID: 6c601f66-58c2-59ee-adf2-7122448fa223

STIX ID: report--6c601f66-58c2-59ee-adf2-7122448fa223

Feed Name: Elastic Security Labs

Threat Score
75/100

Date Published: 2024-10-28

Date Updated: 2026-04-27

...
...

Elastic Security Labs details how several infostealer families (STEALC/VIDAR, METASTEALER, PHEMEDRONE, XENOSTEALER, LUMMA) have bypassed Chrome's Application-Bound Encryption on Windows to steal cookies, describing techniques including in-memory CookieMonster/CookieKatz reads, Chrome DevTools remote debugging, COM elevation/injection using GoogleChromeElevationService, providing IOCs (file hashes), YARA rules, and multiple detection/hunting queries for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.