Executive Summary
Vidar Stealer has introduced a novel mechanism to defeat Google Chrome's Application-Bound Encryption (ABE), which was designed to protect sensitive data like cookies and passwords. By targeting the `v20_master_key` directly in memory, Vidar circumvents traditional disk-based protection layers. This development highlights the ongoing arms race between browser security enhancements and infostealer capabilities.
The attack chain involves creating a memory fork of the browser process using `NtCreateProcessEx` to safely scan for a specific 32-byte signature related to Chromium’s `Encryptor::KeyRing`. Once the encrypted key is located, Vidar utilizes Asynchronous Procedure Call (APC) injection—specifically targeting the `CryptUnprotectMemory` function—to decrypt the key within the browser's own process context. This allows the malware to read the plaintext key from a second forked process for subsequent data exfiltration.
This bypass demonstrates high sophistication in Windows internals abuse. Organizations should prioritize monitoring for suspicious process forking and unusual APC queueing activities, especially those involving common browser processes like Chrome, Edge, or Brave.
