Google Native Client Security/Hacking Contest
ID: 256017b9-987b-59a2-bb75-7ef374dce3c9
STIX ID: report--256017b9-987b-59a2-bb75-7ef374dce3c9
Feed Name: Darknet
DumpBrowserSecrets is a precompiled Windows post-exploitation tool that harvests credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from Chromium-based and Firefox browsers by bypassing App-Bound Encryption (via injection into a headless Chromium process and use of the IElevator COM interface) and handling DPAPI/NSS models for other browsers; it includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication) and outputs structured JSON for rapid credential reuse, enabling fast lateral movement and cloud account takeover. The report includes a usage example, an attack scenario, detection opportunities (monitoring IElevator calls, unusual headless browser instantiation, reads of browser SQLite DBs by non-browser processes), and mitigation advice such as using external credential managers and EDR rules focused on the described behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
