logo

VoidStealer malware steals Chrome master key via debugger trick

ID: 518f98d5-fcc5-5f2e-87d5-1069ed96ce75

STIX ID: report--518f98d5-fcc5-5f2e-87d5-1069ed96ce75

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-03-22

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

VoidStealer is an information-stealer offered as a MaaS that bypasses Chrome's Application-Bound Encryption by starting a suspended hidden browser process, attaching as a debugger, setting hardware breakpoints on a targeted instruction in chrome.dll/msedge.dll during startup, and reading the v20_master_key from memory to decrypt cookies and other protected browser data; researchers link the method to the open-source ElevationKatz tool and report active use in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.