VoidStealer bypasses Chrome protection for stored secrets

Gen Threat Labs has described VoidStealer, malware that abuses a bypass of Chrome's AppBound Encryption protection mechanism. It extracts sensitive browser data such as cookies, credentials and session tokens, decrypts them, and exfiltrates the result to attacker-controlled infrastructure.

What this means for your organisation

The browser is effectively the keyring to a company's cloud services. Stolen session tokens let an attacker skip both login and multi-factor authentication, because the token represents an already approved session. A compromised endpoint can therefore quickly turn into unauthorised access to email, file sharing and business systems without a single password being guessed.

Berigo recommends

  • Treat an infostealer infection as an identity incident: revoke active sessions and rotate credentials, do not merely clean the machine.
  • Shorten session lifetimes for administrative and sensitive services, and require reauthentication when access changes.
  • Bind sign-in to approved and managed devices where the service supports it.
  • Monitor for sign-ins that occur without a preceding authentication event, and make these a defined alert.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch