Hacking Tools, Hacker News & Cyber Security
ID: 07d8d119-d263-54d1-a3c9-423952d2a5a8
STIX ID: report--07d8d119-d263-54d1-a3c9-423952d2a5a8
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests browser-stored credentials and session tokens from major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It implements an App-Bound Encryption bypass for Chromium-based browsers by spawning a headless Chromium process, injecting a DLL via Early Bird APC to use the IElevator COM interface to decrypt the app_bound_encrypted_key, and extracts data from on-disk SQLite/JSON stores; for Firefox it uses NSS decryption directly. The report details extracted data types, operational evasion (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), usage examples, detection opportunities, and mitigation recommendations for enterprise environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
