Google introduced Application-Bound Encryption in Chrome 127 for Windows to reduce browser-cookie theft by malware running as the logged-in user. The protection routes decryption through a privileged service that validates Chrome’s application identity, replacing reliance on DPAPI alone and raising the bar for attackers to obtain SYSTEM privileges or inject code into Chrome. Google began the migration with cookies and plans to extend it to passwords, payment data, and other persistent authentication tokens.
Infostealer families including STEALC/VIDAR, MetaStealer, Phemedrone, XenoStealer, and Lumma adapted by scraping plaintext cookies from Chrome process memory, abusing the Chrome elevation service through COM, injecting into browser processes, or enabling Chrome remote debugging to recover session tokens. Subsequent Hannibal Stealer research also examined the contest between browser protections and credential-stealing malware. Defenders can detect these bypasses through anomalous Chrome child-process activity, memory access, access to cookie files or elevation-service registry keys, localhost debugging traffic, and untrusted code placed in Chrome application directories.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
LUMMA implemented a bypass for Chrome cookie protections and recovered cookies from Chrome 130.0.6723.70 in Elastic's analysis. It reads Chrome memory, pattern-scans chrome.dll for CookieMonster, and extracts plaintext cookies.
METASTEALER announced an updated Chrome-cookie theft capability, claiming support for Chrome 129 and later. Its method obtains the application-bound key and abuses the GoogleChromeElevationService COM interface after impersonating SYSTEM.
XENOSTEALER's Chrome bypass feature was committed. It obtains the application-bound key from Chrome profile data, injects code into Chrome, and invokes the elevation service's DecryptData method from the Chrome process.
STEALC and VIDAR introduced a shared bypass implementation that extracts plaintext Chrome cookies from Chrome process memory. The technique locates Chrome's network service and reads CookieMonster data structures using process-memory access.
A PHEMEDRONE 2.3.2 sample submitted in late September added cookie theft for Chrome 127 and later. It launches Chrome with remote debugging enabled and retrieves plaintext cookies through the DevTools WebSocket interface.
The open-source XENOSTEALER infostealer first appeared, later adding functionality intended to bypass Chrome's Application-Bound Encryption.
Google introduced Application-Bound Encryption for Chrome 127 on Windows, beginning with cookies. The protection uses a SYSTEM-level service to bind decryption to Chrome's application identity rather than relying only on DPAPI.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
netlas.io
Open sourcenetlas.io
Open sourceelastic.co
Open sourcesecurity.googleblog.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.