
StealC v2 Learns to Pick Chromium's App-Bound Encryption Lock
Two newly tracked StealC v2 builds now trip the YARA rule for bypassing Chromium's App-Bound Encryption, signaling the stealer has caught up to browser-side credential hardening. The finding anchors a wider file wave showing a shared loader and UAC-bypass toolkit across five differently labeled malware families.
The newest file wave added to this campaign's tracking includes a StealC v2 build pair that now trips the same YARA rule used to catch tooling built specifically to defeat Chromium's hardened credential store — a capability jump that matters more than any single indicator count added this cycle. A 767KB sample internally labeled as the stealer-loader "marte" variant (0215f734…53624) and a 2.9MB build shipped under the name SilverBulletPro1.5.exe and tracked as "cymulate" (1465e9ea…b5660) both…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read