Researchers reported that the VoidStealer infostealer is using a new debugger-based technique to bypass Google Chrome’s Application-Bound Encryption (ABE) and steal the browser’s v20_master_key from memory. Gen Digital said the malware, offered as a Malware-as-a-Service operation and advertised on forums including HackForums, captures the key at the brief moment it appears in plaintext during browser startup, then uses it to decrypt protected browser data from Chrome and Microsoft Edge.
The method relies on standard Windows debugging APIs and hardware breakpoints rather than code injection, browser memory modification, or elevated privileges, making it quieter than earlier ABE bypasses. Researchers said this is the first publicly reported infostealer observed in the wild using this mechanism, likely adapted from the open-source ElevationKatz project in the ChromeKatz toolset. The finding raises concern that other stealers may adopt the same approach, and defenders were urged to watch for suspicious debugger attachment to browser processes, hidden or headless browser launches, and unexpected memory reads targeting browsers.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
Gen Digital publicly reported that VoidStealer was the first infostealer observed in the wild using a debugger-based method with hardware breakpoints to steal Chrome's master key from memory and decrypt protected browser data. Researchers also assessed the technique was likely adapted from the open-source ElevationKatz/ChromeKatz tooling rather than developed independently.
On March 13, 2026, VoidStealer version 2.0 added a debugger-based technique that captures Chrome and Edge's decrypted v20_master_key from memory during browser startup using standard Windows debugging APIs. The method avoids code injection and elevated privileges, making it stealthier than earlier ABE bypass approaches.
Gen Digital said VoidStealer emerged on dark web forums such as HackForums in mid-December 2025 as a Malware-as-a-Service infostealer and then evolved rapidly through multiple versions.
Google rolled out Application-Bound Encryption (ABE) in Chrome 127 to better protect cookies and other browser secrets by keeping the master key encrypted on disk and validating decryption through the Chrome Elevation Service running as SYSTEM.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcecybersecuritynews.com
Open sourceinfosec.pub
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.