Hacking Tools, Hacker News & Cyber Security
ID: 171a8a00-e285-58df-82c5-7e3e60cc7227
STIX ID: report--171a8a00-e285-58df-82c5-7e3e60cc7227
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets major Windows browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, Firefox). It spawns headless Chromium processes and injects a DLL via Early Bird APC to invoke the IElevator COM interface and decrypt App‑Bound Encryption keys (Chrome 127+), retrieves DPAPI or NSS keys where applicable, and parses browser SQLite/JSON stores to export cookies, saved logins, OAuth tokens, credit cards, autofill and history as structured JSON. The report details technical operation, evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), a realistic attack scenario demonstrating rapid credential theft and session replay, and detection/mitigation guidance such as monitoring IElevator usage, anomalous headless browser instantiation, and using dedicated credential managers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
