cdp-browser-injection
Abuse of the Chrome DevTools Protocol (CDP) to silently control Chromium-based browsers (Chrome, Edge, Brave, Vivaldi) for credential extraction, cookie injection, session hijacking, and contact harvesting. The malware patches browser shortcuts to launch with --remote-debugging-port, then connects via WebSocket to the CDP endpoint to drive the browser programmatically without user knowledge.
Technique Details
- Shortcut patching:
PatchAllShortcuts,PatchSingleShortcutrewrite.lnkfiles to inject--remote-debugging-port^[strings.txt] - Silent browser instances:
StartSilentHarvestInstance,MakeSilentInstanceInvisiblerun headless/hidden Chromium windows withWS_EX_LAYEREDandSetLayeredWindowAttributes^[strings.txt] - CDP operations:
WsSend,WsRecv,CdpEvalQuick,CdpInjectCookies,NavigateViaCdp,CdpReloadPage^[strings.txt] - WhatsApp / Gmail / Outlook automation:
ExecuteWhatsAppCdp,ExecuteGmailCdp,ExecuteOutlookCdpfor contact harvesting and message relay ^[strings.txt]
Cross-References
- sky-jamaica — family using this technique extensively
- email-harvesting-via-cdp — related email-harvesting pattern