EXECUTIVE SUMMARY:
Researchers have discovered a malware targeting Google Chrome has led to the development of several stealers, such as METASTEALER, PHEMEDRONE, XENOSTEALER, and LUMMA. These malware variants bypass Chrome’s latest security measures to steal sensitive data, such as cookies. As Chrome continues to implement stronger protections, these attackers adapt their techniques to continue their malicious activities.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Researchers have discovered a malware targeting Google Chrome has led to the development of several stealers, such as METASTEALER, PHEMEDRONE, XENOSTEALER, and LUMMA. These malware variants bypass Chrome’s latest security measures to steal sensitive data, such as cookies. As Chrome continues to implement stronger protections, these attackers adapt their techniques to continue their malicious activities.[emaillocker id="1283"]
METASTEALER uses advanced techniques to circumvent Chrome's encryption protections. It impersonates the SYSTEM token and interacts with a service called GoogleChromeElevationService to decrypt cookies. The malware extracts encryption keys from Chrome’s Local State or LocalPrefs.json files and is capable of handling both new and old encryption methods. PHEMEDRONE, on the other hand, leverages a Windows SmartScreen vulnerability and opens a remote debugging session with Chrome. It uses the Chrome DevTools Protocol to retrieve cookies in plaintext by communicating with Chrome over port 9222. XENOSTEALER takes a similar approach but injects code into an already running Chrome process to extract encrypted cookie data, which it decrypts using the GoogleChromeElevationService. LUMMA creates a visible Chrome process and scans Chrome’s memory to extract cookie data by identifying patterns in the chrome.dll file. Once the cookies are located, it dumps them in clear text from memory and sends them to the attacker.
Although Chrome’s security measures have become more robust, malware authors continue to innovate, developing bypass techniques to steal sensitive data like cookies. The effectiveness of these attacks depends on malware’s ability to exploit vulnerabilities and evade detection. It should prioritize monitoring for abnormal behaviors on endpoints and implementing detection mechanisms to safeguard against these evolving threats.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Execution | T1559 | Inter-Process Communication |
| Defense Evasion | T1055 | Process Injection |
| Credential Access | T1539 | Steal Web Session Cookie |
| T1555 | Credentials from Password Stores | |
| Discovery | T1082 | System Information Discovery |
| T1057 | Process Discovery |
REFERENCES:
Kindly exclude this link in the advisory mail:
https://www.elastic.co/security-labs/katz-and-mouse-game