KuinaExtractor Rust Infostealer Evolves With Chrome ABE Bypass and k0to Rebrand

Over the past six months, cybersecurity researchers have tracked an undocumented information stealer written in Rust. Initially dubbed KuinaExtractor, this malware has transformed from a rough early build into a highly sophisticated threat.

Evidence suggests the malware is the work of a single operator, likely based in Vietnam. The developer has continually updated the code, recently rebranding it as “k0to” while adding advanced evasion techniques.

The malware first appeared in December 2025. Even in its early stages, it was highly capable and targeted Roblox cookies, Steam sessions, cryptocurrency wallets, and Discord tokens.

Most notably, it included a full bypass for Chrome’s App-Bound Encryption (ABE) by impersonating the LSASS process to recover master keys. Early versions used Discord webhooks for data exfiltration and relied on a simple UAC bypass for privilege escalation.

KuinaExtractor Evolves With Bypass

By January 2026, the developer had completely rebuilt the stealer. This rewrite introduced heavy reconnaissance capabilities.

The malware began querying hardware details, enumerating WiFi networks, dumping Windows Credential Manager data, and forcefully terminating 17 different browser processes.

Data exfiltration also shifted from Discord webhooks to a dedicated Telegram bot. In March 2026, a hardened production build emerged that remained active for months.

KuinaExtractor Evolves With Bypass (Source: threatray)
KuinaExtractor Evolves With Bypass (Source: threatray)

The core cookie-theft routine was updated to support ChaCha20-Poly1305 encryption for newer Chrome versions. The malware expanded its list of browser targets to around 40, including the Vietnamese CocCoc browser.

Furthermore, it gained broad virtual machine (VM) and sandbox detection capabilities, frustrating security analysts.

The most significant shift occurred on June 17, 2026. A new build surfaced, dropping the “Kuina” moniker in favor of “k0to”.

This version prioritizes stealth over new data-theft features. It uses a self-contained HTTP stack with its own certificate authorities, avoiding the system’s TLS store entirely.

It also encrypts its internal strings using a 28-byte XOR key and actively scans PowerShell window titles for malware analysis tools.

While developing the main malware line, the threat actor also tested parallel experiments. In January, a leaner version called KuinaCookieExtractor appeared.

KuinaExtractor Evolves With Bypass (Source: threatray)
KuinaExtractor Evolves With Bypass (Source: threatray)

This variant focused heavily on gaming and communication platforms, stealing data from Minecraft, FileZilla, and Telegram.

It relied on Discord for data exfiltration and implemented lighter anti-analysis checks, logging a warning when detecting a VM before continuing execution.

Another short-lived project, known as Zenith, surfaced in late April. This build accidentally left debug logging enabled, which recorded detailed traces on the infected machine and revealed an explicit author attribution block.

Shortly after, a “Zenith Stealer” control panel appeared, hosted on a Vietnamese IP address, though the developer quickly abandoned it, threatray said.

Security analysts have successfully grouped these various builds by focusing on distinct code similarities. Throughout the malware’s lifespan, several consistent markers have tied the projects together.

These include shared mutex names, specific build-host paths left in the compiled binaries, and a recurring set of developer Telegram handles.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories