logo

Hands in the Cookie Jar: Dumping Cookies with Chromium’s Remote Debugger Port

ID: acc4ed86-5745-5dbe-9641-de98638a7054

STIX ID: report--acc4ed86-5745-5dbe-9641-de98638a7054

Feed Name: SpecterOps Blog

Date Published: 2020-12-17

Date Updated: 2026-04-30

Author: Justin Bui

...
...

This report explains a Chromium cookie-theft technique that abuses the browser’s remote debugging interface to enumerate pages/extensions and extract decrypted session cookies, enabling credential-less access and potential MFA bypass (ATT&CK T1539). It introduces the Golang tool WhiteChocolateMacademiaNut to automate the process on Windows and macOS, discusses operational caveats (e.g., headless issues and session-restore use), and recommends detections such as monitoring for browsers launched with --remote-debugging-port; it also notes that Chromium added mitigations in 2023.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.