VoidStealer Debuts Novel Debugger Bypass for Chrome and Edge Encryption
ID: 68002bfd-60b0-5d99-9970-07a0927fd730
STIX ID: report--68002bfd-60b0-5d99-9970-07a0927fd730
Feed Name: securityonline.info
Researchers at Gen Threat Labs uncovered VoidStealer, the first in-the-wild infostealer that bypasses browser Application-Bound Encryption by acting as a debugger and setting hardware breakpoints to capture the v20_master_key from Chrome/Edge memory. The technique requires no code injection or privilege escalation, makes detection harder, and leaves behavioral fingerprints (unauthorized debugger reads); researchers recommend monitoring for unauthorized debugging of browsers and other behavioral detection to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
