Infostealer malware
Malware that copies the browser's saved sessions and sends them to whoever runs it.
Families like Lumma, RedLine and VidarBROWSER DECOY · EARLY ACCESS
Infostealer malware and hostile extensions copy the cookies that keep you signed in, then replay them from another machine. No password or two-step code needed. The Vantuz Browser Decoy keeps one fake session in Chrome or Edge, next to the real ones. If anyone uses it, Vantuz alerts you.
HOW IT WORKS
Nothing changes for the person using the browser. The decoy sits quietly next to their real sessions until someone tries to use it.
For one browser, an owner or admin creates an activation code in Vantuz and the person pastes it into the extension. The code works once, for 24 hours. For a fleet, IT pushes a policy through Google Admin or Microsoft Intune.
The Vantuz Browser Decoy holds one synthetic login session on a decoy domain Vantuz controls, and renews it every 6 hours. Your real sessions are never touched.
When anyone replays the decoy session, the decoy domain answers with an ordinary 404. Vantuz opens an incident, emails you and lays out what to do first.
WHAT IT CATCHES
A copied session skips the password and the two-step code. The decoy does not care which tool did the copying: it fires when the copy is used.
Malware that copies the browser's saved sessions and sends them to whoever runs it.
Families like Lumma, RedLine and VidarAnyone who gets onto the computer or into the browser profile and takes its cookies.
Remote access trojans, copied profilesBrowser add-ons that turn hostile, or were built to harvest cookies from the browser they live in.
Fake or hijacked add-onsAnyone replaying a copied session from their own machine, whatever tool did the copying.
MITRE ATT&CK T1550.004WHAT IT NEVER DOES
Any company should ask what an extension can see. This one can reach two addresses: the Vantuz control API and the decoy domain. Chrome only lets an extension touch cookies on the sites it can reach, so your real sessions, tabs and browsing stay out of its sight.
cookiesTo keep its one decoy cookie on the decoy domainstorageTo keep its own settings and statealarmsTo renew the decoy session every 6 hourswebRequestIt cannot watch or change your trafficWHEN IT FIRES
The decoy domain answers with an ordinary 404, so the attacker learns nothing. Vantuz opens an incident with the first source address, country, network and software, maps it to MITRE ATT&CK T1550.004 (Web Session Cookie) and scores it at least High (62). The alert reaches you by email, with the full investigation in the app.
The decoy session lived only in the browser on the finance laptop, and someone replayed it from an address in the United Kingdom. The decoy domain answered with an ordinary 404, so they learned nothing.
HONEST LIMITS
A decoy gives you a certain signal, not the complete picture. Here is exactly where the edges are.
Attackers often sort through stolen sessions and use only the ones they want. If nobody replays the decoy, it stays quiet, so silence does not prove nothing was taken.
Malware can copy the cookie jar and sit on it. The decoy speaks up the moment someone replays the session, not before.
A replay tells you the browser's sessions were very likely copied. It cannot list which real ones went, so treat them all as exposed and sign the person out everywhere.
Anyone who opens the decoy address in that browser, on purpose or by following a link to it, fires it as well. That is why the first step is to confirm with the person.
TWO WAYS IN
Both end the same way: one decoy session in each browser, renewed every 6 hours and watched by Vantuz.
For one person, or to try it first. An owner or admin creates the code in Vantuz, the person pastes it into the extension, and the decoy is armed.
For the browsers your company manages. IT pushes a policy through Google Admin or Microsoft Intune. New browsers can join for 30 days; browsers that joined keep renewing.
Revoking a decoy disarms it on the server immediately. The extension removes its cookie at its next check.
Use it only on browsers your company controls or has authorised, and let the people who use them know.
EARLY ACCESS
The browser decoy is in early access until Google approves its Chrome Web Store listing. Tell us how many browsers you would like to cover and how you manage them, and we will set you up in the pilot.
SEE IT LIVE
Thirty minutes, your environment. We plant a decoy, trigger it on purpose,
and you watch the whole response happen. No slides.
No. It asks for three permissions, cookies, storage and alarms, and it can reach only two addresses: the Vantuz control API and the decoy domain. Chrome only lets an extension touch cookies on the sites it can reach, so your real sessions, tabs and history stay out of its sight. No content scripts, no remote code, no analytics.
Not yet. The browser decoy is in early access, and it goes on the Chrome Web Store once Google approves the listing. Request early access and we will set it up with you.
Google Chrome and Microsoft Edge on desktop, version 120 or later. It is a Manifest V3 extension. In Edge, turn on Allow extensions from other stores before installing it from the Chrome Web Store.
The decoy domain answers with an ordinary 404, so the attacker learns nothing. Vantuz opens an incident with the first source address, country, network and software, maps it to MITRE ATT&CK T1550.004 (Web Session Cookie) and scores it at least High (62). You get an email, and the full investigation is in the app.
Normal browsing never touches the decoy session: it lives on a domain nobody at your company uses. The exceptions are someone opening the decoy address in that browser, on purpose or through a link to it. That is why the first step is always to confirm with the person.
Revoke the decoy in Vantuz. The server disarms it immediately, and the extension removes its cookie at its next check. Then remove the extension or the policy as you would any other.