PULSE NAME
Glove Stealer bypasses Chrome's App-Bound Encryption to steal cookies
WHITE AlienVault 2024-11-16 Modified: 2024-11-18
15
IOCs
MEDIUM VOLUME
Researchers have discovered a new .NET-based information stealer called Glove Stealer that targets browser extensions and local software to steal sensitive data like cookies, passwords, and cryptocurrency wallets. It uses a novel technique to bypass Chrome's App-Bound encryption by exploiting the IElevator service. The malware is distributed through phishing campaigns and requires administrative privileges to place its module in Chrome's Program Files directory. Once executed, it contacts a command-and-control server to exfiltrate harvested data.
Indicators of Compromise (9 / 15 total)
All FileHash-SHA256 URL hostname CVE
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2024-4058 2024-11-16
CVE CVE-2024-40711 2024-11-16
CVE CVE-2024-40766 2024-11-16
CVE CVE-2024-43093 2024-11-16
CVE CVE-2024-43461 2024-11-16
CVE CVE-2024-45519 2024-11-16
CVE CVE-2024-4577 2024-11-16
CVE CVE-2024-47575 2024-11-16
CVE CVE-2024-6327 2024-11-16