Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Chrome-App-Bound-Encryption-Decryption — Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens from Chrome, Edge, Brave & Avast - fileless, user-mode, no admin required. | Kitploit
Tools/GitHubGitHub/xaitax/chrome-app-bound-encryption-decryption
Encryption/Decryption ToolsPassword AttacksExploitationData ExfiltrationInformation GatheringPost-ExploitationCryptographyRed Teaming

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
xaitax/chrome-app-bound-encryption-decryption

Chrome-App-Bound-Encryption-Decryption

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens from Chrome, Edge, Brave & Avast - fileless, user-mode, no admin required.

View RepositoryWebsite
1.7k292337 months agoReviewed by Kitploit

ChromElevator (Chrome App-Bound Encryption Decryption)

🚀 Overview

Build Status License Platform Languages Ask DeepWiki

A post-exploitation tool demonstrating a complete, in-memory bypass of Chromium's App-Bound Encryption (ABE). This project utilizes Direct Syscall-based Reflective Process Hollowing to launch a legitimate browser process in a suspended state, stealthily injecting a payload to hijack its identity and security context. This Living-off-the-Land (LOTL) technique subverts the browser's own security model. The fileless approach allows the tool to operate entirely from memory, bypassing user-land API hooks to decrypt and exfiltrate sensitive user data (cookies, passwords, payments) from modern Chromium browsers.

If you find this research valuable, I'd appreciate a coffee:
ko-fi

🛡️ Core Technical Pillars

This tool's effectiveness is rooted in a combination of modern, evasion-focused techniques:

  • Direct Syscalls for Evasion: Bypasses EDR/AV user-land hooks on standard WinAPI functions by invoking kernel functions directly. The engine dynamically resolves syscall numbers at runtime using Hell's Gate technique with hash-based function matching (no plaintext syscall names in the binary).

  • Direct Syscall-Based Process Hollowing: A stealthy process creation and injection technique. Instead of injecting into a high-traffic, potentially monitored process, it creates a new, suspended host process. This significantly reduces the chances of detection, as all memory manipulations occur before the process begins normal execution.

  • Fileless In-Memory Payload: The payload DLL never touches the disk on the target machine. It is embedded as a ChaCha20-encrypted compile-time byte array with compile-time derived keys, decrypted in-memory, and reflectively loaded, minimizing its forensic footprint and bypassing static file-based scanners.

  • Reflective DLL Injection (RDI): A stealthy process injection method that circumvents LoadLibrary for the main payload, thereby evading detection mechanisms that monitor module loads. The self-contained bootstrap loader maps PE sections, performs relocations, and resolves imports from memory.

  • Target-Context COM Invocation: The lynchpin for defeating App-Bound Encryption. By executing code within the trusted browser process, we inherit its identity and security context, allowing us to make legitimate-appearing calls to the ABE COM server and satisfy its path-validation security checks.

⚙️ Features

Core Functionality

  • 🔓 Full user-mode decryption of cookies, passwords, payment methods, IBANs, and Google OAuth tokens.
  • 📁 Discovers and processes all user profiles (Default, Profile 1, etc.).
  • 📝 Exports all extracted data into structured JSON files, organized by profile.
  • 🔍 Comprehensive browser fingerprinting with system information.

Stealth & Evasion

  • 🛡️ Fileless Payload Delivery: In-memory decryption and injection of an encrypted embedded payload.
  • 🛡️ Direct Syscall Engine: Bypasses common endpoint defenses by avoiding hooked user-land APIs for all process operations.
  • 🛡️ Hash-Based Syscall Resolution: No plaintext Nt*/Zw* function names in binary—uses compile-time DJB2 hashes.
  • 🛡️ Compile-Time Key Derivation: Encryption keys derived from build metadata, unique per build.
  • 🛡️ PE Header Destruction: Post-injection PE headers obliterated with pseudo-random data to evade memory scanners.
  • 🛡️ IPC Mimicry: Browser-specific named pipe patterns that blend with legitimate browser IPC traffic.
  • 🤫 Process Hollowing: Creates a benign, suspended host process for the payload, avoiding injection into potentially monitored processes.
  • 👻 Reflective DLL Injection: Stealthily loads the payload without suspicious LoadLibrary calls.
  • 🔒 Non-Intrusive File-Lock Bypass: Uses syscall-based handle duplication to access locked SQLite databases without terminating browser processes. Optional --kill flag available for full process termination.
  • 💼 No Admin Privileges Required: Operates entirely within the user's security context.

Compatibility & Usability

  • 🌐 Works on Google Chrome, Brave, Edge, & Avast Secure Browser.
  • 💻 Natively supports x64 and ARM64 architectures.
  • 🚀 Standalone Operation: Automatically creates a new browser process to host the payload, requiring no pre-existing running instances.
  • 📁 Customizable output directory for extracted data.
image

📦 Supported & Tested Versions

BrowserTested Version (x64 & ARM64)
Google Chrome144.0.7559.133
Google Chrome Beta145.0.7632.18
Brave1.86.148 (144.1.86.148)
Microsoft Edge145.0.3800.36
Avast Secure Browser143.0.33371.147

Note: Chrome/Brave/Edge 144+ use the new IElevator2 COM interface. This tool automatically uses IElevator2 when available and falls back to IElevator for older versions. Avast Secure Browser uses a custom IElevatorChrome interface with an extended vtable (12 methods, DecryptData at offset 104).

🔍 Feature Support Matrix

This matrix outlines the extraction capabilities for each supported browser.

FeatureGoogle ChromeMicrosoft EdgeBraveAvast Secure Browser
Cookies✅ ABE✅ ABE✅ ABE✅ ABE
Passwords✅ ABE✅ ABE✅ ABE✅ ABE
Payment Methods✅ ABE✅ ABE✅ ABE✅ ABE
IBANs✅ ABE❌ N/A✅ ABE✅ ABE
Auth Tokens✅ Google❌ N/A❌ N/A❌ N/A

🔬 Technical Workflow

The tool's execution is focused on stealth and efficiency, built around a Direct Syscall-based Reflective Hollowing process. This approach ensures that few high-level API calls are made and that the payload operates from within a legitimate, newly created browser process.

Stage 1: The Injector (chromelevator.exe)

Download Tool