VoidStealer malware steals Chrome master key via debugger trick
ID: 518f98d5-fcc5-5f2e-87d5-1069ed96ce75
STIX ID: report--518f98d5-fcc5-5f2e-87d5-1069ed96ce75
Feed Name: Bleeping Computer
Threat Score
VoidStealer is an information-stealer offered as a MaaS that bypasses Chrome's Application-Bound Encryption by starting a suspended hidden browser process, attaching as a debugger, setting hardware breakpoints on a targeted instruction in chrome.dll/msedge.dll during startup, and reading the v20_master_key from memory to decrypt cookies and other protected browser data; researchers link the method to the open-source ElevationKatz tool and report active use in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
