C&CMembers
C&C

Stealc v2 Chromium Bypass Moves to Active Campaign in Vietnam

Three confirmed Stealc v2 samples carrying a built-in bypass for Google's 2024 app-bound encryption are operating inside a multi-stage financial-theft chain targeting Vietnam-region victims. The toolchain pairs browser credential harvesting with cryptocurrency clipboard hijackers and an Amadey loader, all communicating through a dedicated single-operator hosting block registered in October 2024.

Jun 5, 2026, 08:07 (UTC+9)Last seenJun 5, 2026Severity100ByCTX TeamIOC36MITRE31RegionsVN

Three Windows executables circulating in a Vietnam-region campaign have been confirmed by sandbox analysis and six independent YARA rules as carrying Stealc v2's built-in bypass for Chromium app-bound encryption — a credential-protection mechanism Google introduced in 2024 specifically to block the kind of browser-password extraction that infostealer markets had relied on for years.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence