C&CMembers
C&C

Stealc v2 Bypasses Chrome 127 Encryption in Crypto-Theft Campaign

A financially motivated operator has deployed a multi-stage credential-theft toolkit built around two Stealc v2 payloads that implement a working bypass for Google's post-Chrome-127 app-bound encryption. The campaign pairs the stealer core with a clipboard hijacker, a PyInstaller-wrapped Python trojan, and a cryptocurrency-themed shellcode dropper, routing stolen data through PHP endpoints on two bulletproof-hosting autonomous systems in Germany and the Netherlands.

Jun 17, 2026, 08:34 (UTC+9)Last seenJun 17, 2026Severity100ByCTX TeamIOC26MITRE51RegionsCA

A financially motivated operator has deployed a multi-stage credential-theft campaign built around two Stealc v2 payloads that implement a post-Chrome-127 app-bound encryption key decryptor — a deliberate capability upgrade that allows the malware to extract browser-stored credentials from modern Chrome profiles that earlier Stealc variants and most competing infostealers cannot reach.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence