VoidStealer is a Windows malware-as-a-service infostealer marketed since at least December 2025. Version 2.0, introduced in March 2026, bypasses Chromium Application-Bound Encryption to obtain the browser v20 master key without requiring elevated privileges or direct code injection. It launches a hidden browser process, attaches as a debugger, places hardware breakpoints on browser decryption code, and reads the plaintext key from browser memory when decryption occurs. The technique targets Google Chrome and Microsoft Edge and enables decryption of protected browser data, including saved credentials and session cookies. VoidStealer also implements a separate, noisier browser-injection method that invokes the browser elevation COM interface to decrypt protected data. Its debugger-based method has been assessed as adapted from the public ElevationKatz project. Theft of browser credentials and session cookies can enable account takeover and unauthorized access to authenticated services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Чтобы воспользоваться этим «окном возможностей», вредоносное ПО подключается к процессу Chrome как отладчик...
Чтобы воспользоваться этим «окном возможностей», вредоносное ПО подключается к процессу Chrome как отладчик...
When the breakpoint triggers, the R15 register for Chrome or R14 register for Edge holds a direct pointer to the v20_master_key, which VoidStealer then extracts using just two ReadProcessMemory calls.
It targets the moment when Chrome needs to decrypts data and uses it to sign into a website or to access saved credentials, she noted. To do this, Chrome exposes the master key in plaintext in browser memory; VoidStealer authors figured out a way to take advantage of that brief window of opportunity.
Особенную ценность для злоумышленников представляют собой так называемые сессионные файлы cookie... кража таких файлов позволяет злоумышленнику использовать уже подтвержденную сессию без ввода логина и пароля от лица жертвы.
The variant, introduced in VoidStealer version 2.0 on March 13, 2026, uses a debugger-based technique to silently extract encrypted browser credentials directly from memory... VoidStealer currently targets both Google Chrome and Microsoft Edge.
It then listens for debug events through WaitForDebugEvent, monitoring each DLL as it loads into the browser’s memory space. Once chrome.dll or msedge.dll loads, VoidStealer uses ReadProcessMemory to scan the DLL’s .rdata section...
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as contextual comparison for its similar resolver mechanism; it was not identified in the analyzed collection.
Infostealer mentioned only as another malware observed using the Chrome App-Bound Encryption key-extraction technique.
VoidStealer is referenced as another infostealer previously discussed in relation to ABE inner workings.
Referenced only as a comparison family that did not technically match the observed sample.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.