Amatera/ACR Stealer Chrome ABE Bypass - Credential Theft to Exfiltration

Detects unauthorized, non-browser processes accessing sensitive Chromium-based browser credential files (e.g., 'Local State', 'Login Data', 'Cookies') followed by suspicious outbound network connections. This pattern is characteristic of credential-stealing malware (infostealers) like Amatera, Lumma, and Remus.