logo

Dough No! Revisiting Cookie Theft

ID: 76843586-ac43-5001-9ad8-0d9154e70aef

STIX ID: report--76843586-ac43-5001-9ad8-0d9154e70aef

Feed Name: SpecterOps Blog

Date Published: 2025-08-27

Date Updated: 2026-04-30

Author: Andrew Gomez

...
...

This report explains Chrome and Edge’s shift to App-Bound encryption for cookie protection and details four practical techniques adversaries can still use to steal cookies: leveraging the DecryptData COM interface, reproducing SYSTEM-bound decryption (including Chrome-specific PostProcessData flows on domain-joined and non-domain hosts), enabling remote debugging to extract cookies via DevTools, and loading custom extensions to harvest cookies. It offers accompanying detections such as DPAPI debug event auditing, Sysmon CreateRemoteThread and ProcessAccessed monitoring, process creation flag detection for remote-debugging and load-extension switches, and extension ID auditing, while providing tooling references (e.g., Cookie-Monster and helper scripts) for red and blue teams.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.