Malware Circumvents Google Chrome’s App-Specific Encryption

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Advanced Malware Discovered Bypassing Chrome’s App-Bound Encryption

Emerging Malware Threat Bypasses Chrome’s App-Bound Encryption

In a groundbreaking discovery, researchers from Cyble have unveiled a sophisticated malware attack that ingeniously circumvents Google Chrome’s App-Bound Encryption, a security measure designed to protect user cookies from infostealer malware. The recent findings, detailed in a blog post this week, reveal that this advanced threat could potentially compromise user accounts and sensitive information.

The attack employs dual injection techniques, cunningly disguising malicious files to evade detection. Cyble’s analysis highlights that attackers hide a malicious LNK file within a ZIP file designed to look like a PDF. Additionally, they manipulate a malicious XML project file to appear as a harmless PNG image, tricking unsuspecting users into executing the payload.

Central to the malware’s effectiveness is its ability to leverage fileless execution and scheduled task persistence. Once activated, the malware utilizes Microsoft Build Engine (MSBuild.exe) to deploy harmful C# code directly in memory, making detection incredibly challenging, according to the researchers. Notably, the double injection technique—combining Process Injection and Reflective DLL Injection—allows the malware to operate stealthily without leaving traces on the disk.

Targeting organizations in Vietnam, particularly in the telemarketing and sales sectors, the malware uses the Telegram Web API for command and control, enabling the threat actor to dynamically change communication channels. This connection allows for a range of malicious activities, including bypassing Chrome App-Bound Encryption to steal sensitive data, including cookies and login credentials.

Cyble advises organizations to implement robust security measures, including user training, strict email attachment filtering, and application whitelisting, to mitigate risks associated with this sophisticated threat. The full analysis contains vital insights into the malware’s infection chain and mitigation strategies, underscoring the imperative for enhanced digital vigilance.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Cyberattackers exploit AI hype with phishing campaigns impersonating platforms like ChatGPT and Claude

Recent research from Microsoft Threat Intelligence reveals a surge in cyberattacks leveraging the hype surrounding artificial intelligence (AI). Cybercriminals are increasingly impersonating well-known AI...

Apple launches 2026 device lineup featuring foldable iPhone Duo and new Apple Watch models.

Apple Launches 2026 Device Lineup with Foldable iPhone Duo Apple has officially unveiled its 2026 device portfolio, introducing a range of innovative products including the...

September 2026 Patch Tuesday Addresses 22 Critical Vulnerabilities in Microsoft Products

September 2026 Patch Tuesday: A Critical Update for Microsoft Products This month, Microsoft addressed a staggering 22 critical vulnerabilities across its product suite, with significant...

Sea Machines to supply autonomy kits under contract with U.S. Special Operations Forces

Sea Machines Robotics has secured a five-year Indefinite Delivery Indefinite Quantity (IDIQ) contract to provide its autonomy kits to U.S. Special Operations Forces (SOF). The...