HomeSecurity“Sryxen” malware manages to bypass Chrome encryption

“Sryxen” malware manages to bypass Chrome encryption

A new infostealer called Sryxen has appeared on the underground malware market, targeting Windows systems with advanced techniques to collect browsing credentials and sensitive data.

See also: Battlefield 6: Fake versions distribute infostealer

Sryxen

Sold as Malware-as-a-Service , this C++ malware demonstrates how modern infostealers are adapting to overcome browser security improvements—particularly Google Chrome 's recently integrated App-Bound Encryption . Sryxen operates as a fast, predatory credential harvester, designed to execute quickly without installing any persistence mechanisms on the infected system.

The malware targets Chrome versions 127 and above, where Google introduced App-Bound Encryption to protect cookies and sensitive browser data.

See also: Rhadamanthys infostealer: Sudden shutdown

Raccoon Infostealer Malware

Instead of trying to bypass this encryption directly, Srixen adopts a more innovative tactic: it launches Chrome in headless mode and uses the Dev Tools Protocol to request decrypted cookie data, effectively bypassing the security measure.

Security researchers at DeceptIQ found that Sryxen uses multiple layers of protection to evade detection and analysis.

The malware implements code encryption based on Vectored Exception Handling, keeping its main payload encrypted while in storage and decrypting it only during execution via exception handling mechanisms. This technique makes static analysis difficult, as the malicious code appears as garbage data when examined without execution.

See also: LeakyInjector and LeakyStealer steal cryptocurrencies and browsing history

“Sryxen” malware manages to bypass Chrome encryption

Additionally, infostealer incorporates six different anti-debug checks , such as NtGlobal Flag inspection and PEB analysis , terminating execution if debugging tools are detected.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS