Chrome App-Bound Encryption Bypass
Technique for decrypting Chrome's App-Bound Encryption (ABE) credential database, introduced in Chrome 114 to harden Login Data against DPAPI-only decryption. Malware bypasses ABE by retrieving the app-bound key from the Chrome Local State or via COM elevation.
Detection / Fingerprint
- Go function names:
main.GetAppBoundKey,main.StartAPPB,main.decryptAPPB - File access:
%LOCALAPPDATA%\Google\Chrome\User Data\Local State - Registry access:
SOFTWARE\Microsoft\Windows\CurrentVersion\Run(persistence for elevated key retrieval) - COM interaction:
CoCreateInstance,CoInitializeExfor Chrome Elevator COM interface
Implementation Patterns
The AFK Stealer sibling bd6dead7 includes a dedicated ABE bypass module:
main.GetAppBoundKey— retrieves the app-bound key blobmain.StartAPPB— initializes the ABE decryption contextmain.decryptAPPB— decrypts credentials using the app-bound keymain.decryptDataEdge,main.decryptDataBrave— browser-specific variants
This suggests the malware can handle both the legacy DPAPI path and the newer ABE path for Chromium-based browsers.
Defensive Detection
- EDR: non-Chrome process reading
Local Statewith intent to parse JSON and extractapp_bound_encrypted_key - EDR: process invoking Chrome's
IElevatorCOM interface without being Chrome itself - File integrity: monitor for unauthorized access to
Login DataandLocal Statefiles
Cross-References
- Observed in: afk-stealer
bd6dead7f5a0ec51 - Related: browser-credential-harvesting — cross-family technique page
- Related: chrome-app-bound-encryption-bypass — if a dedicated page exists for this concept