logo

Dragging Secrets Out of Chrome: NTLM Hash Leaks via File URLs

ID: 5868c71e-4865-58bf-95d8-316fad7448da

STIX ID: report--5868c71e-4865-58bf-95d8-316fad7448da

Feed Name: TrustedSec blog

Threat Score
50/100

Date Published: 2025-09-25

Date Updated: 2026-05-01

...
...

This report presents "DragonHash", a proof-of-concept that abuses Chromium drag-and-drop DownloadURL behavior to induce Windows to initiate NTLM authentication requests to an attacker-controlled responder, allowing capture of NTLM hashes; it includes PoC code, a demo site, and notes on limitations (user interaction and browser download settings).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.