Hacking Tools, Hacker News & Cyber Security
ID: 24a4c43d-cdf6-5964-b5ed-c18b9f4f38f4
STIX ID: report--24a4c43d-cdf6-5964-b5ed-c18b9f4f38f4
Feed Name: Darknet
DumpBrowserSecrets is a precompiled Windows post‑exploitation tool that harvests browser‑stored credentials and session tokens from major Chromium‑ and Gecko‑based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, Firefox). It bypasses Chrome App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface (and uses DPAPI/NSS handling for other browsers), includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, file‑handle duplication), and outputs structured JSON to facilitate credential replay and lateral movement; the report covers usage, supported browsers, attack scenarios, detection signals, and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
