Sysmon detection for Chrome and Edge process injection during CDP-enabled post-exploitation
Defensive Guidance
Summary
Hide ▲
Show ▼
A concrete Sysmon hunt for chrome.exe and msedge.exe injection now helps Windows defenders spot CDP-enabled post-exploitation before authenticated browser sessions are abused. The guidance ties the control to Event ID 8 and Event ID 10, which surface suspicious thread creation and cross-process access against browser processes. Because the technique assumes prior code execution, this monitoring is aimed at post-compromise operator activity rather than a browser vulnerability.
Related Happenings
CDP-Enable-BOF activates Chrome DevTools Protocol inside live Windows browsers for post-exploitation session access
Technical Analysis
H score23
First: 14.08.2026 14:07
Last: 14.08.2026 14:07
Sources 1
How related:
Cybersecurity researchers have detailed a post-exploitation technique that enables the Chrome DevTools Protocol (CDP) inside a running Google Chrome or Microsoft Edge process on Windows, allowing an operator to access cookies, saved data, and authenticated browser sessions.
About this happening:
CDP-Enable-BOF now enables Chrome DevTools Protocol access inside a live Google Chrome or Microsoft Edge process on Windows, raising the risk of cookie theft...
CDP-Enable-BOF activates Chrome DevTools Protocol inside live Windows browsers for post-exploitation session access
Technical AnalysisHow related: Cybersecurity researchers have detailed a post-exploitation technique that enables the Chrome DevTools Protocol (CDP) inside a running Google Chrome or Microsoft Edge process on Windows, allowing an operator to access cookies, saved data, and authenticated browser sessions.
About this happening: CDP-Enable-BOF now enables Chrome DevTools Protocol access inside a live Google Chrome or Microsoft Edge process on Windows, raising the risk of cookie theft...
ClickFix AmnesiaStealer distribution campaign targeting mac users
Campaign
H score22
First: 14.08.2026 13:45
Last: 14.08.2026 13:45
Sources 1
About this happening:
A ClickFix campaign is distributing AmnesiaStealer to macOS users through a counterfeit GitHub "Download for macOS" page and a copy-and-paste command that launches...
ClickFix AmnesiaStealer distribution campaign targeting mac users
CampaignAbout this happening: A ClickFix campaign is distributing AmnesiaStealer to macOS users through a counterfeit GitHub "Download for macOS" page and a copy-and-paste command that launches...
Latest development: 16.08.2026 18:07
Jamf described AmnesiaStealer's stream_module and remote_stream commands, which copy a victim's Chromium profile into a hidden headless browser and open WebSocket and Chrome DevTools Protocol channels through webSocketDebuggerUrl. The operator can issue navigation and mouse commands, receive live screencasts, and export or import cookies to operate online portals inside the victim's authenticated sessions on Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium.
XCSSET v40 macOS malware activity via compromised Xcode projects
Malware Activity
H score30
First: 04.08.2026 22:03
Last: 04.08.2026 22:03
Sources 1
About this happening:
XCSSET v40 has resurfaced on macOS through compromised Xcode projects and GitHub repositories, putting thousands of users at risk of credential theft and data...
XCSSET v40 macOS malware activity via compromised Xcode projects
Malware ActivityAbout this happening: XCSSET v40 has resurfaced on macOS through compromised Xcode projects and GitHub repositories, putting thousands of users at risk of credential theft and data...
MsaRAT backdoor routes C2 through Chrome or Edge
Malware Activity
H score23
First: 23.07.2026 12:59
Last: 23.07.2026 12:59
Sources 1
About this happening:
Chaos ransomware is using msaRAT, a Rust backdoor, to route C2 through headless Chrome or Microsoft Edge on a compromised Windows host. Cisco Talos...
MsaRAT backdoor routes C2 through Chrome or Edge
Malware ActivityAbout this happening: Chaos ransomware is using msaRAT, a Rust backdoor, to route C2 through headless Chrome or Microsoft Edge on a compromised Windows host. Cisco Talos...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware Activity
H score23
First: 24.06.2026 23:58
Last: 24.06.2026 23:58
Sources 1
About this happening:
The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware ActivityAbout this happening: The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
Timeline
-
14.08.2026 14:07 2 articles · 3d ago
SpecterOps recommends Sysmon hunts for chrome.exe and msedge.exe injection
Detection Ioc UpdateSpecterOps described CDP-Enable-BOF, a post-exploitation technique that enables the Chrome DevTools Protocol inside a live Google Chrome or Microsoft Edge process on Windows so an operator can reach cookies, saved data, and authenticated browser sessions after prior code execution on the host. The firm advised defenders to look for process injection targeting chrome.exe and msedge.exe using Sysmon Event IDs 8 and 10.
Show sources
- Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers — thehackernews.com — 14.08.2026 14:07
- Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers — thehackernews.com — 14.08.2026 14:07