Skip to content
Droid ToolsDroid Tools
Home
About UsContact
Editorial PolicyReview Policy
Privacy PolicyCookie PolicyTerms & Conditions
⌘K
Search
FacebookX (Twitter)InstagramThreadsBlueskyTikTokYouTubeRedditTelegramRSS Feed
Droid Tools

Droid Tools covers the latest Android news, device reviews, app updates, and OS guides. Stay informed with hands-on coverage from mobile tech experts.

Explore

  • News
  • Apps
  • OS
  • Phones
  • Reviews

Legal & Info

  • About Us
  • Contact
  • Editorial Policy
  • Review Policy
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy
  • Affiliate Disclosure
  • Disclaimer
  • HTML Sitemap
  • XML Sitemap
© 2026 Droid Tools. All rights reserved.
Home/News/Chrome’s cookie encryption has been broken by the new Glove infostealer malware.
News

Chrome’s cookie encryption has been broken by the new Glove infostealer malware.

The new Glove Stealer malware can collect browser cookies by getting past Google Chrome's Application-Bound (App-Bound) encryption. This information-stealing virus is "very simple and contains limited obfuscation or protective features," suggesting that it is most likely still in its early stages of development, according to Gen Digital security researchers who first discovered it when looking …

Robert Haba
Nov 16, 20243 min read
Robert Haba
Robert Haba
Founder · Editor-in-Chief
Robert Haba is the founder and editor-in-chief of Droid Tools. A lifelong gadget enthusiast with over a decade following the Android ecosystem, he built this publication to cut through the noise and give readers honest, real-world coverage of the tech they actually use.
X
Profile →
Chrome’s cookie encryption has been broken by the new Glove infostealer malware.
0%
Share on XFacebookBluesky
Follow on Google
Trust this source on GoogleAlways see our reviews and tech guides first in search results
Add trusted source

The new Glove Stealer malware can collect browser cookies by getting past Google Chrome’s Application-Bound (App-Bound) encryption. This information-stealing virus is “very simple and contains limited obfuscation or protective features,” suggesting that it is most likely still in its early stages of development, according to Gen Digital security researchers who first discovered it when looking into a recent phishing attempt.

During their attacks, the threat actors used social engineering tactics similar to those used in the ClickFix infection chain, where potential victims get tricked into installing malware using fake error windows displayed within HTML files attached to the phishing emails.

Glove Stealer

Cookies from Firefox and Chromium-based browsers (such as Chrome, Edge, Brave, Yandex, and Opera) can be extracted and exfiltrated by the Glove Stealer.NET virus.

Additionally, it can collect password information from Bitwarden, LastPass, and KeePass, cryptocurrency wallets from browser extensions, 2FA session tokens from Google, Microsoft, Aegis, and LastPass authenticator apps, and emails from mail programs like Thunderbird.

“Other than stealing private data from browsers, it also tries to exfiltrate sensitive information from a list of 280 browser extensions and more than 80 locally installed applications,” said malware researcher Jan Rubín.

“These extensions and applications typically involve cryptocurrency wallets, 2FA authenticators, password managers, email clients and others.”

You May Also Like
Recommended
1

Exynos 2700 enters mass production, but the Galaxy S27 Ultra’s chip is still undecided

Galaxy 27 series
2

What contractors should look for before hiring someone to build a business website

website design
3

Fake ChatGPT custom GPT used to spread malware via Google ads

Fake ChatGPT custom GPT used to spread malware via Google ads

Glove Stealer bypasses Google’s App-Bound encryption cookie-theft safeguards, which were implemented by Chrome 127 in July, in order to steal credentials from Chromium web browsers. It accomplishes this by employing a supporting module that decrypts and recovers App-Bound encrypted keys using Chrome’s own COM-based IElevator Windows service (running with SYSTEM rights), as outlined by security researcher Alexander Hagenah last month.

To install this module in the Program Files directory of Google Chrome and utilize it to recover encrypted keys, the virus must first obtain local administrator capabilities on the infected PCs.

However, despite its attractive appearance, Glove Stealer is still in its early stages of development since, as researcher g0njxa told BleepingComputer in October, it is a simple technique that most other information thieves have already accomplished to collect cookies from all Google Chrome versions.

Russian Panda, a malware analyst, previously told BleepingComputer that Hagenah’s technique resembles early workarounds used by other viruses following Google’s introduction of Chrome App-Bound encryption.

When Google told BleepingComputer last month that “this code [xaitax’s] requires admin credentials, which shows that we have successfully upped the degree of access required to properly pull off this type of assault,” Unfortunately, the number of active information-stealing malware campaigns has not decreased significantly despite the requirement for administrator access to circumvent App-Bound encryption.

Attacks have only increased since July when Google first implemented App-Bound encryption, targeting potential victims via vulnerable drivers, zero-day vulnerabilities, malvertising, spearphishing, StackOverflow answers, and fake fixes to GitHub issues.

Trust this source on GoogleAlways see our reviews and tech guides first in search results
Add trusted source
Tags:#app#chrome#cybersecurity#info#malware#security
Recommended Deals
1 / 5
Google Pixel Watch 5 (45mm)

Google Pixel Watch 5 (45mm)

5.0
529.99
Buy on Amazon
* As an Amazon Associate, Droid Tools earns from qualifying purchases. Read our editorial policy
Robert Haba
Robert HabaFounder · Editor-in-Chief
X

Robert Haba is the founder and editor-in-chief of Droid Tools. A lifelong gadget enthusiast with over a decade following the Android ecosystem, he built this publication to cut through the noise and give readers honest, real-world coverage of the tech they actually use.

Next Story in News

Exynos 2700 enters mass production, but the Galaxy S27 Ultra’s chip is still undecided

The Exynos 2700 has reportedly entered volume production at Samsung, with output running more than 10% above the Exynos 2600's as the Galaxy S27 Pro joins the lineup. The Galaxy S27, S27+, and Pro are expected to carry the Exynos 2700 in Korea and Europe, with that rollout coming alongside reports that the Galaxy S27 […]

→

Latest Stories

Android code hints at “Unlock with Google Account” PIN recovery option01

Android code hints at “Unlock with Google Account” PIN recovery option

02

Exynos 2700 enters mass production, but the Galaxy S27 Ultra’s chip is still undecided

03

Samsung’s AI glasses confirmed for a November launch

04

What contractors should look for before hiring someone to build a business website

Amazon Deals
5.0
Google Pixel Watch 5 (45mm)

Google Pixel Watch 5 (45mm)

Best Price
529.99
Buy

Top Deals

Google’s Pixel Referral Program is back with 10% off and Store credit

Deal
Google’s Pixel Referral Program is back with 10% off and Store credit

Pixel Watch 5 vs. Pixel Watch 4: what actually changed

Deal
Pixel Watch 5 vs. Pixel Watch 4: what actually changed

Apple Watch Series 12 vs Pixel Watch 5: how they compare

Deal
Apple Watch Series 12 vs Pixel Watch 5: how they compare
Recommended stories

Continue reading

More from this category →
Galaxy 27 series
NewsOct 6, 2026

Exynos 2700 enters mass production, but the Galaxy S27 Ultra’s chip is still undecided

The Exynos 2700 has reportedly entered volume production at Samsung, with output running more than 10% above the Exynos 2600's as the Galaxy S27 Pro joins the lineup. The Galaxy S27, S27+, and Pro are expected to carry the Exynos 2700 in Korea and Europe, with that rollout coming alongside reports that the Galaxy S27 […]

By Robert Haba
website design
NewsOct 5, 2026

What contractors should look for before hiring someone to build a business website

A contractor’s website has to do more than look polished on a phone. It should help a potential customer understand what the business does, where it works, and how to request a quote. Getting those basics right can be harder than it sounds, especially when a business owner is comparing developers, website platforms, and marketing […]

By Robert Haba
Fake ChatGPT custom GPT used to spread malware via Google ads
NewsOct 2, 2026

Fake ChatGPT custom GPT used to spread malware via Google ads

Cybersecurity researchers at Huntress have uncovered a campaign where hackers built a custom ChatGPT model to trick people into launching malware on their own PCs, turning one of OpenAI's own features against its users. The campaign starts on Google search. Anyone searching for “chatgpt” might click a sponsored ad at the top of the results […]

By Robert Haba
kirin 9050
NewsSep 11, 2026

Huawei Kirin 9050 Pro chipset: full specs and what’s new

Huawei has released its new high-performance Kirin 9050 Pro chipset, and details about the silicon's architecture are now available across CPU, GPU, NPU, modem, security, and cooling. CPU, GPU, and NPU upgrades The chip's LinxiCore CPU supports simultaneous multi-threading and delivers a 24% gain in peak single-core performance alongside a 52% gain in multi-core concurrent […]

By Robert Haba
Next in queue

Read the next article

The next story loads as you reach the end. You can also load it using the button.

Comments & Discussions

Join the conversation! We use Disqus to handle comments. Click the button below to load the comment section.