unclassified-msvc-browser-credential-harvester
MSVC 14.50 x64 DLL browser credential harvester with Chrome App-Bound Encryption (ABE) bypass. Single export Bootstrap. No packing, no obfuscation, no Authenticode. Statically links SQLite 3.49.1. No network IAT — writes harvested data to local JSON files for companion exfiltration stage.
Build / RE
- Language: C++ (MSVC 14.50, Visual Studio 2022)
- Format: PE32+ x64 DLL, Windows GUI subsystem
- Packing: None
- Obfuscation: None
- Anti-analysis: Minimal (
IsDebuggerPresent,QueryPerformanceCountertiming,CreateMutexWsingle-instance) - Signing: Unsigned
- GuardCF: Enabled (unusual for malware)
- POGO: Profile-Guided Optimization debug directory present
- SQLite: 3.49.1 statically linked (source ID
873d4e274b...) - Export:
Bootstrap@0x18002FA88with embedded PEB-walking API resolution stub
Deploy / ATT&CK
- T1555.003 — Credentials from Password Stores: Browser (Chrome, Brave, Edge, Firefox)
- T1552.004 — Private Keys (Chrome App-Bound Encryption bypass)
- T1082 — System Information Discovery (
RtlGetVersion,GetUserNameA,GetComputerNameA) - T1057 — Process Discovery (
CreateToolhelp32Snapshot) - T1622 — Debugger Evasion (
IsDebuggerPresent) - T1497.001 — Time-Based Evasion (
QueryPerformanceCounter,GetTickCount) - T1055 — Process Injection (DLL form +
Bootstrapexport with reflective loader pattern)
Capabilities
chrome-app-bound-encryption-bypass— decryptsapp_bound_encrypted_keywith ABE, falls back to legacy DPAPIbrowser-credential-harvesting— cookies, passwords, saved cards, IBANs, OAuth tokens via SQLitesqlite-local-credential-store— statically linked SQLite 3.49.1 for in-process database queriesbcrypt-aes-key-management—BCryptOpenAlgorithmProvider,BCryptGenerateSymmetricKey,BCryptDecryptdpapi-com-interop—CoInitializeEx+CoCreateInstancefor DPAPICryptUnprotectDatapeb-walking-api-resolution—Bootstrapexport contains ROR13 export hash resolution stubjson-fingerprint-staging— writesfingerprint.json,cookies.json,passwords.json, etc.single-instance-mutex-gating—CreateMutexW+WaitForSingleObjectguardcf-camouflage— Control Flow Guard enabled for legitimate-software masquerade
Known Samples
| SHA-256 Prefix | Build | Notes |
|---|---|---|
9d3d5ac0 |
Apr 22 2026 | Primary sample. ASTER_KEY: debug prefix. No siblings confirmed. |
Related
- browser-credential-harvesting — cross-family concept
- chrome-app-bound-encryption-bypass — technique page for ABE bypass
- peb-walking-api-resolution — technique page for the Bootstrap export stub
- stealc — commodity C++ infostealer with similar build stack but different capabilities (keylogging, named pipes, WINHTTP C2)
- chromeloader-pulsar-rat — .NET RAT with
chrome_decrypt.dllmodule but different build stack