Hacking Tools, Hacker News & Cyber Security
ID: 24450203-825a-53c1-aa03-803100f4824d
STIX ID: report--24450203-825a-53c1-aa03-803100f4824d
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool targeting major Windows browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It spawns a headless browser, injects a DLL to use the IElevator COM interface to decrypt app_bound_encrypted_key for Chromium builds, extracts SQLite/JSON stored secrets (passwords, cookies, OAuth tokens, credit cards, autofill, history), and writes structured JSON output; the report also documents evasion techniques, an attack scenario demonstrating cloud account/session takeover risks, and guidance for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
