typetechniqueconfidencehighcreated2026-08-08updated2026-08-08cdpbrowser-manipulationdefense-evasioncollectiondotnet

cdp-browser-injection

Abuse of the Chrome DevTools Protocol (CDP) to silently control Chromium-based browsers (Chrome, Edge, Brave, Vivaldi) for credential extraction, cookie injection, session hijacking, and contact harvesting. The malware patches browser shortcuts to launch with --remote-debugging-port, then connects via WebSocket to the CDP endpoint to drive the browser programmatically without user knowledge.

Technique Details

  • Shortcut patching: PatchAllShortcuts, PatchSingleShortcut rewrite .lnk files to inject --remote-debugging-port ^[strings.txt]
  • Silent browser instances: StartSilentHarvestInstance, MakeSilentInstanceInvisible run headless/hidden Chromium windows with WS_EX_LAYERED and SetLayeredWindowAttributes ^[strings.txt]
  • CDP operations: WsSend, WsRecv, CdpEvalQuick, CdpInjectCookies, NavigateViaCdp, CdpReloadPage ^[strings.txt]
  • WhatsApp / Gmail / Outlook automation: ExecuteWhatsAppCdp, ExecuteGmailCdp, ExecuteOutlookCdp for contact harvesting and message relay ^[strings.txt]

Cross-References