Vidar Stealer Chromium KeyRing Memory Scan via NtReadVirtualMemory

Detects Vidar Stealer scanning the memory of a forked browser process for the Chromium KeyRing 32-byte pattern using NtReadVirtualMemory and NtQueryVirtualMemory to locate the v20_master_key across MEM_COMMIT and MEM_PRIVATE regions. This behavior is indicative of an information stealer attempting to exfiltrate sensitive browser data.