securityonline.info 6/25/2026, 9:01:14 AM · external

Vidar ABE Bypass Technique Steals Browser Keys

Vidar ABE Bypass Technique Steals Browser Keys
CyberSIXT Evidence Panel
Primary Source gendigital.com

GEN Digital researchers have identified a new technique used by Vidar infostealer malware to bypass Application-Bound Encryption (ABE) in web browsers. Vidar extracts the master key from memory to decrypt sensitive data, targeting user credentials effectively. The malware employs process forking to obtain browser data without interacting directly with live memory, leading to a controlled environment that captures a static memory snapshot.

It utilizes Asynchronous Procedure Calls for decryption, allowing it to steal user data and send it back to the attackers. Key recommendations for defense include monitoring for suspicious browser processes and unusual APC injections.

View Primary Source Via securityonline.info

Article by CyberSIXT