New PowerShell stealer targets developers via fake Claude Code installer, exploiting Chrome 144's IElevator2 interface to bypass App-Bound Encryption and harvest browser credentials from compromised workstations.
Technical breakdown:
• Campaign uses lookalike install pages with altered PowerShell commands, domains registered April 2026
• 600KB obfuscated loader targets Chromium browsers (Chrome, Edge, Brave, Vivaldi, Arc)
• 4608-byte native helper reflectively injected into browser processes to invoke IElevator2 COM interface
• Transcription error in Edge IElevator2 IID (Data3 field) creates unique detection signature
• Persistence via scheduled task polling C2 every minute, excludes Iran 🇮🇷/Russia 🇷🇺/CIS regions
Detection strategy:
• Helper binary contains no network/file/crypto imports - all malicious activity in PowerShell layer
• Monitor for PowerShell spawning native code injection into browser processes
• Alert on IElevator2 interface calls from non-browser processes
Enable PowerShell Constrained Language Mode and script block logging. Filter newly registered domains at web proxy.
#DFIR_Radar