Parallel Log-in Brute Forcing/Password Cracking Tool
ID: 18fbca87-3473-5e0c-8209-9768f9672d73
STIX ID: report--18fbca87-3473-5e0c-8209-9768f9672d73
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation tool that harvests browser-stored secrets (cookies, saved logins, OAuth refresh tokens, credit cards, autofill data, history, bookmarks) from Chromium-based browsers and Firefox; it bypasses Chrome App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface, and handles DPAPI and NSS models for other browsers. The report documents usage, extracted outputs (JSON), evasion features, a realistic attack scenario, detection opportunities (process injection, IElevator calls, SQLite reads), and mitigation recommendations, noting the tool is targeted at red-team engagements but represents a significant credential-theft capability if misused.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
