Vidar Stealer Bypassing Chrome Application-Bound Encryption
Score: 8/10

Vidar Stealer Bypassing Chrome Application-Bound Encryption

Vidar Stealer utilizes memory forking and APC injections to extract and decrypt the Chromium v20_master_key, bypassing Application-Bound Encryption.

Executive Summary

Vidar Stealer has introduced a novel mechanism to defeat Google Chrome's Application-Bound Encryption (ABE), which was designed to protect sensitive data like cookies and passwords. By targeting the `v20_master_key` directly in memory, Vidar circumvents traditional disk-based protection layers. This development highlights the ongoing arms race between browser security enhancements and infostealer capabilities.

The attack chain involves creating a memory fork of the browser process using `NtCreateProcessEx` to safely scan for a specific 32-byte signature related to Chromium’s `Encryptor::KeyRing`. Once the encrypted key is located, Vidar utilizes Asynchronous Procedure Call (APC) injection—specifically targeting the `CryptUnprotectMemory` function—to decrypt the key within the browser's own process context. This allows the malware to read the plaintext key from a second forked process for subsequent data exfiltration.

This bypass demonstrates high sophistication in Windows internals abuse. Organizations should prioritize monitoring for suspicious process forking and unusual APC queueing activities, especially those involving common browser processes like Chrome, Edge, or Brave.

Key Details

Threat Name

Vidar Stealer

Affects

—

Adversary

—

Malware/Tools

Vidar, Lumma, VoidStealer

Report Score

8out of 10
Quality Score
Good
IOC Quality4
TTP Details9
Detection Guidance6
Enterprise Relevance8
Clarity & Structure9
Technical Depth10

Sources