HomeSecurityKatz Stealer targets Chrome, Edge, Brave and Firefox

Katz Stealer targets Chrome, Edge, Brave, and Firefox

A sophisticated new credential-stealing malware, known as Katz Stealer , has emerged as a serious threat to users of popular web browsers , demonstrating advanced capabilities that allow it to bypass modern security technologies and exfiltrate sensitive identification data.

See also: Authorities disrupted Lumma Stealer malware infrastructure

Katz Stealer

This malware-as-a-service operation specifically targets Chrome, Microsoft Edge, Brave, and Firefox browsers , implementing a multi-layered attack strategy that combines social engineering techniques with innovative evasion methods to steal user credentials , cryptocurrency wallets, and data from communication platforms .

This threat is a worrying development in cybercriminal tactics, as it successfully bypasses Chrome's recently implemented App-Bound Encryption — a security feature designed to protect stored passwords and cookies from unauthorized access.

See also: Gremlin Stealer: New info-stealer advertised on Telegram

The operators of Katz Stealer have developed methods to extract decryption keys directly from browser processes, effectively nullifying one of the most powerful security mechanisms used in browsers today.

Katz Stealer targets Chrome, Edge, Brave, and Firefox

The malware also demonstrates extreme flexibility in how it targets its victims, systematically collecting data from gaming platforms like Steam, communication tools like Discord and Telegram, email clients like Outlook, as well as various cryptocurrency wallet applications.

Nextron Systems researchers identified this emerging threat through in-depth analysis of its infection mechanisms and behavioral patterns, documenting the malware's complex, multi-phase installation process.

See also: UAC-0226 deploys GIFTEDCROOK Stealer via Excel

The team's research revealed that Katz Stealer uses advanced analysis evasion techniques, such as geofencing mechanisms that prevent the malware from executing in Commonwealth of Independent States (CIS), VM detection, and sandbox evasion strategiesthat analyze screen resolution and system uptime to identify research environments.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS