# stealer — RedTeam credential harvester (Windows)

Operator-authorized engagements only. Cross-compiled from Linux via cargo-xwin.

## What it does

Collects from a compromised Windows host (user context, no admin needed):

- **Chromium passwords** — Chrome, Edge, Brave, Opera, OperaGX, Vivaldi, Yandex.
  v10/v11 AES-256-GCM (master key from Local State, DPAPI-unwrapped) + legacy
  raw-DPAPI blobs. v20 (Chrome 127+ app-bound) detected and skipped.
- **Cookies** — same browsers, Netscape format per-browser, Chromium epoch → unix.
- **Credit cards** — Web Data `credit_cards` table (DPAPI-decrypted numbers).
- **Files** (optional) — Telegram Desktop `tdata`, KeePass dir, Exodus, Electrum
  wallets (recursive, depth ≤3, size 1B–5MB).
- **System info** — computer name, user, CPU count.

Firefox NSS (key4.db/logins.json) is **not yet implemented** — profiles are
enumerated but skipped.

## Output

```
%TEMP%\loot\<COMPUTERNAME>\
    Passwords.txt        SOFT/URL/USER/PASS (format C-ish)
    Cookies\<browser>.txt  Netscape cookie format
    CreditCards.txt
    SystemInfo.txt
    Files\...            tdata, kdbx, wallets
%TEMP%\loot\<COMPUTERNAME>.zip   (deflate, miniz_oxide)
```

Layout matches the project's `aggregate_breach.py` ingestion expectations
(Format C: Browser/URL/Username/Password with `---` separators — the
`Passwords.txt` renderer emits `SOFT:/URL:/USER:/PASS:` + `---------------`).

## Build

```bash
# one-time env: clang-cl shim (cc-rs needs it for rusqlite/bundled sqlite)
mkdir -p ~/.local/bin
printf '#!/bin/sh\nexec clang-16 --driver-mode=cl "$@"\n' > ~/.local/bin/clang-cl
ln -sf /usr/bin/llvm-lib-16 ~/.local/bin/lib.exe
export PATH="$HOME/.local/bin:$PATH"

cargo xwin build --release --target x86_64-pc-windows-msvc
# artifact: target/x86_64-pc-windows-msvc/release/stealer.exe
```

## Run

```
stealer.exe                       # default: collect all, zip to %TEMP%\loot
stealer.exe --stealth             # single-thread + 20ms jitter per profile
stealer.exe --no-files            # skip Files/ (tdata/kdbx/wallets)
stealer.exe --out C:\out          # custom output dir
stealer.exe --verbose             # stderr stats (default: fully silent)
```

## OPSEC profile

- No CreateRemoteThread/WriteProcessMemory/VirtualAllocEx/QueueUserAPC.
- Imports: kernel32, ntdll, crypt32 (`CryptUnprotectData`, `CopyFileW`,
  `GetSystemInfo`). No network APIs — local collection only.
- All sensitive strings (SQL queries, browser paths, env vars, file targets)
  XOR-obfuscated at compile time (`obf!` macro) — 0 IOC strings in .rdata.
- Debug paths remapped (`--remap-path-prefix`) — no `/root/...` leaks.
- crt-static: no vcruntime DLL dependency.
- Silent by default; no event-log writes, no console output without `--verbose`.
- Locked DBs: `CopyFileW` shadow-copy to temp, read, delete. No VSS, no
  `reg save`, no lsass touch.

## Verification status

- `cargo test --target x86_64-unknown-linux-gnu`: 12/12 PASS (cfg-gated pure
  logic: GCM round-trip, key extraction, layout renderers, zip CRC32/structure).
- `cargo xwin clippy --target x86_64-pc-windows-msvc -- -D warnings`: clean.
- PE32+ x86-64, 8 sections, ~1.9MB (bundled sqlite dominates size).
- Strings sweep: 0 hits for origin_url/os_crypt/Login Data/Telegram/KeePass/etc.
- **Not yet run on a real Windows host** — behavioral verification of the
  DPAPI/SQLite/CopyFileW paths requires a Windows VM (see project methodology:
  cfg-gated code is compile-gated only).

## Known limitations / next steps

1. Firefox NSS decryption (key4.db + logins.json, PBKDF2+3DES/AES) — planned.
2. Chrome v20 app-bound decryption (needs COM IElevation or path validation
   bypass) — currently skipped on classify.
3. No exfiltration — operator retrieves the zip via existing channel.
4. `--stealth` jitter is per-profile only; file collection is not jittered.
5. Sysmon EID surface: file enumeration burst in `tdata`/wallet dirs — use
   `--stealth` on monitored hosts (see redteam-windows-tradecraft rule 3).
