logo

Vidar Infostealer Bypasses Google Chrome’s ABE Encryption via APC Injection

ID: 8b558d4f-78fe-569c-9aa4-6c0786f04bb5

STIX ID: report--8b558d4f-78fe-569c-9aa4-6c0786f04bb5

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-06-20

Date Updated: 2026-06-20

Author: Eswar

...
...

Gen Threat Labs reports that the Vidar infostealer has evolved to bypass Chrome’s 2024 Application-Bound Encryption (ABE) by forking browser processes (via NtCreateProcessEx with a null section) to create copy-on-write memory snapshots, scanning for Chromium’s Encryptor::KeyRing entries (the v20_master_key), and using APC injection to invoke CryptUnprotectMemory in-process to decrypt and extract the master key; the malware then re-encrypts memory to avoid forensic traces and includes an IoC SHA-256 for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.