PULSE NAME
Glove Stealer bypasses Chrome's App-Bound Encryption to steal cookies
WHITE AlienVault 2024-11-16 Modified: 2024-11-18
15
IOCs
MEDIUM VOLUME
Researchers have discovered a new .NET-based information stealer called Glove Stealer that targets browser extensions and local software to steal sensitive data like cookies, passwords, and cryptocurrency wallets. It uses a novel technique to bypass Chrome's App-Bound encryption by exploiting the IElevator service. The malware is distributed through phishing campaigns and requires administrative privileges to place its module in Chrome's Program Files directory. Once executed, it contacts a command-and-control server to exfiltrate harvested data.
Indicators of Compromise (3 / 15 total)
All FileHash-SHA256 URL hostname CVE
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 2bf6fab237ab58ae6cfe78f9a61ab6dcaf55f437cb7a77878e2e6aae3b208e80 2024-11-16
FileHash-SHA256 56da496329d54587c31119d8878a7831a9814a92839aa6a9873ceeb91575b11a 2024-11-16
FileHash-SHA256 86ad4082e086a0b9a22dc91a16d0d9be38232975ab4d3d035224fb6d6cc7a44c 2024-11-16