-256 algorithm Google 's addition of the AES to encrypt cookies and passwords in the Chrome browser appears to be not very effective against infostealers .
The developers behind the malicious software that steals data from web browsers have evolved tools to overcome this obstacle that Google has placed on the Chrome browser.
Even the infostealer AZORult has received patches that make it compatible with Chrome version 80.
Now, a new information-stealing software is being released that, according to advertisements on hacking forums, can bypass the new level of encryption.
Before Chrome 80
Google released Chrome 80 in early February. Until its release, cookies and passwords on Windows were encrypted via DPAPI in the operating system.
Raveed Laeb, an executive at KELA, said that Chrome still relies on this method but has also introduced an additional layer of encryption.
The data is initially encrypted with the AES standard and the key is encrypted using the CrypProtectData DPAPI. The process is reversed and the AES-256 key is obtained with the CryptUnprotectData function.
Google explained why it made this change, which limited infostealers for a short time:
“We made some changes that will allow us to isolate Chrome's network stack in its own sandboxed process. As part of these changes we changed the password / cookies encryption algorithm and the storage mechanisms”.
In this way, Google claims to make it more difficult for hackers who try to steal data with various programs.

The new method is not very effective
The addition of AES encryption to the Chrome browser initially caused some obstacles for malicious software, but this did not last long.
Shortly after the appearance of the new Chrome, updates were publicly announced for at least four infostealers, which had adapted to the new mechanism, and were able to steal "protected" information.
Four days after the release of the new Chrome, the creator of the KPot infostealer reported that he had already created an updated version of the malware that could bypass encryption. The upgraded tool was immediately put up for sale for $90.
The creators of Raccoon, an infostealer that can grab data from nearly 60 applications (including all popular browsers), announced that they have also managed to bypass the new security layer of Chrome 80.
However, some developers of new infostealers have also appeared, claiming that they can also bypass Chrome 80's encryption. For example, an advertisement was found on a Russian hacking forum for Redline, a new infostealer.
AZORult is still “alive»
AZORult was one of the top 10 malware in 2019. Its original creator "abandoned" it in December 2018. However, other hackers continued to use it .
AZORult ++ was first mentioned in May 2019 and the version 3.4 was recently announced.
There are many variants of this infostealer and one of them now appears to be compatible with Chrome 80.
This version was announced in early March. The new version essentially comes from an unknown source and for that reason it is not widely adopted, but is used in small campaigns.
Chrome 80 tried to block infostealers but most managed to bypass encryption and thus can operate effectively.
