Executive Summary
The Drun Backdoor, often deployed via a loader referred to as 'Chromelevator', is a sophisticated two-stage information stealer first analyzed in detail in mid-2024. The threat is characterized by its high degree of evasion, employing direct system calls to bypass User Mode API hooking and integrating custom logic to circumvent Google Chrome's 'App-Bound Encryption' (introduced in version 127). The malware's modular design allows it to harvest a wide array of sensitive data including browser credentials, Discord tokens, Telegram sessions, Steam authentication files, and webcam captures.
Technical analysis reveals a complex attack chain where the 'Chromelevator' loader (drun.exe) performs architecture validation and reflective injection of an encrypted payload (payload.dll). The stealer component leverages an embedded SQLite engine to query browser databases directly, avoiding dependencies on external libraries. Exfiltration is primarily handled through Discord webhooks, with Gofile.io acting as a fallback for larger data archives. This malware represents a significant threat to personal and corporate data due to its ability to hijack authenticated sessions (Telegram, Steam, Roblox) and bypass modern browser security controls.
The urgency of this threat is high for organizations with diverse software environments, as it specifically targets various browsers (Chrome, Edge, Opera, Brave, Firefox) and communication platforms. The use of direct syscalls and encrypted payloads indicates a developer familiar with bypassing EDR and sandbox environments, necessitating robust behavioral detection strategies beyond simple IOC matching.
