VoidStealer Steals Chrome Secrets Without Injection or Privilege Escalation
ID: 51a54f04-7962-59f9-856a-6e2428fbc5b3
STIX ID: report--51a54f04-7962-59f9-856a-6e2428fbc5b3
Feed Name: GBHackers
Threat Score
**Executive summary:** VoidStealer v2.0 is a sophisticated infostealer observed in the wild that bypasses Chrome's Application‑Bound Encryption (ABE) by attaching as a debugger to browser processes, setting hardware breakpoints on the ABE decryption path, extracting the v20_master_key from registers, and offline‑decrypting ABE‑protected cookies and credentials—achieving full credential theft without requiring SYSTEM privileges or code injection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
