Hacking Tools, Hacker News & Cyber Security
ID: 0f2c27be-6ca4-51d5-a29b-0414353de990
STIX ID: report--0f2c27be-6ca4-51d5-a29b-0414353de990
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation credential-harvesting tool that extracts saved passwords, cookies, OAuth tokens, credit cards and browsing history from Chromium-based and Firefox browsers. It bypasses Chrome App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL (Early Bird APC) to call the IElevator COM interface to decrypt keys, uses DPAPI/NSS handling for other browsers, and includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, custom SQLite parser). The report covers usage, attack scenarios, detection opportunities, and mitigations and frames the tool as a red-team utility that also demonstrates a significant real-world credential exposure risk when browser-stored secrets are trusted.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
