216.73.217.80

Glove Stealer bypasses Chrome's App-Bound Encryption to steal cookies

· Published 16/11/2024 03:18 · Modified 18/11/2024 17:33

Export JSON

Essential information

Published
16/11/2024 03:18
Modified
18/11/2024 17:33
Tags
2024-11-16 chrome encryption bypass glove stealer information stealer malware phishing
Related entities
13 techniques (mitre), 1 malware

Description

Researchers have discovered a new .NET-based called that targets browser extensions and local software to steal sensitive data like cookies, passwords, and cryptocurrency wallets. It uses a novel technique to bypass 's App-Bound encryption by exploiting the IElevator service. The is distributed through campaigns and requires administrative privileges to place its module in 's Program Files directory. Once executed, it contacts a command-and-control server to exfiltrate harvested data.

External references