Chrome’s cookie encryption has been broken by the new Glove infostealer malware.

Robert Haba
Robert Haba
3 min read
Chrome’s cookie encryption has been broken by the new Glove infostealer malware.
Trust this source on Google
Add trusted source

The new Glove Stealer malware can collect browser cookies by getting past Google Chrome’s Application-Bound (App-Bound) encryption. This information-stealing virus is “very simple and contains limited obfuscation or protective features,” suggesting that it is most likely still in its early stages of development, according to Gen Digital security researchers who first discovered it when looking into a recent phishing attempt.

During their attacks, the threat actors used social engineering tactics similar to those used in the ClickFix infection chain, where potential victims get tricked into installing malware using fake error windows displayed within HTML files attached to the phishing emails.

Glove Stealer

Cookies from Firefox and Chromium-based browsers (such as Chrome, Edge, Brave, Yandex, and Opera) can be extracted and exfiltrated by the Glove Stealer.NET virus.

Additionally, it can collect password information from Bitwarden, LastPass, and KeePass, cryptocurrency wallets from browser extensions, 2FA session tokens from Google, Microsoft, Aegis, and LastPass authenticator apps, and emails from mail programs like Thunderbird.

“Other than stealing private data from browsers, it also tries to exfiltrate sensitive information from a list of 280 browser extensions and more than 80 locally installed applications,” said malware researcher Jan Rubín.

“These extensions and applications typically involve cryptocurrency wallets, 2FA authenticators, password managers, email clients and others.”

Glove Stealer bypasses Google’s App-Bound encryption cookie-theft safeguards, which were implemented by Chrome 127 in July, in order to steal credentials from Chromium web browsers. It accomplishes this by employing a supporting module that decrypts and recovers App-Bound encrypted keys using Chrome’s own COM-based IElevator Windows service (running with SYSTEM rights), as outlined by security researcher Alexander Hagenah last month.

To install this module in the Program Files directory of Google Chrome and utilize it to recover encrypted keys, the virus must first obtain local administrator capabilities on the infected PCs.

However, despite its attractive appearance, Glove Stealer is still in its early stages of development since, as researcher g0njxa told BleepingComputer in October, it is a simple technique that most other information thieves have already accomplished to collect cookies from all Google Chrome versions.

Russian Panda, a malware analyst, previously told BleepingComputer that Hagenah’s technique resembles early workarounds used by other viruses following Google’s introduction of Chrome App-Bound encryption.

When Google told BleepingComputer last month that “this code [xaitax’s] requires admin credentials, which shows that we have successfully upped the degree of access required to properly pull off this type of assault,” Unfortunately, the number of active information-stealing malware campaigns has not decreased significantly despite the requirement for administrator access to circumvent App-Bound encryption.

Attacks have only increased since July when Google first implemented App-Bound encryption, targeting potential victims via vulnerable driverszero-day vulnerabilitiesmalvertising, spearphishingStackOverflow answers, and fake fixes to GitHub issues.

Featured Deal
1 / 5
👑A good choice
Apple iPhone 17 Pro

Apple iPhone 17 Pro

4.8 / 5.0
$1,012.97$1,099.00-8%
Buy
Google Pixel Watch 4

Google Pixel Watch 4

4.8 / 5.0
396.00$499.99-21%
Buy
Google Pixel 9

Google Pixel 9

5.0 / 5.0
$544.99$799.00-32%
Buy
Budget
Nothing Phone (4a) Pro

Nothing Phone (4a) Pro

4.5 / 5.0
$494.99$599.00-17%
Buy
DEAL!
Samsung Galaxy Watch Ultra (2025)

Samsung Galaxy Watch Ultra (2025)

5.0 / 5.0
$449.99$649.99-31%
Buy
* As an Amazon Associate, Droid Tools earns from qualifying purchases. Disclosure.
Founder · Editor-in-Chief
Robert Haba is the founder and editor-in-chief of Droid Tools. A lifelong gadget enthusiast with over a decade following the Android ecosystem, he built this publication to cut through the noise and give readers honest, real-world coverage of the tech they actually use.

Comments & Discussions

Join the conversation! We use Disqus to handle comments. Click the button below to load the comment section.

Keep Reading

Practically every streaming service not named Netflix has turned to bundling over the past few years, with competitors teaming up to deliver combo packs like Disney+ and HBO Max. No service has been bundled quite as often as Peacock, though, and YouTube Premium subscribers are now joining the long list of ways to gain access […]

peacock youtube premium
NewsRobert HabaJuly 27, 2026

The invites for Google’s Pixel event just landed, and the leaks have already laid out a stacked rundown of the Google Pixel 11 and Tensor G6. Tech forums have already made up their minds. Going by the leaks, the G6 looks like a regression. The G6 comes up short on CPU cores, and its graphics […]

google tensor g6 image
NewsRobert HabaJuly 27, 2026

Google is set to unveil the Pixel 11 family on August 12, and just ahead of that event, the company’s VP of Devices and Services, Shakil Barkat, has confirmed what many were expecting: prices are going up across the lineup. Google Confirms Pixel Price Adjustments Barkat explained that, like other consumer tech companies, Google is […]

Google Pixel 11
NewsRobert HabaJuly 26, 2026