logo

Fully Automated WPA PSK Handshake Capture Script

ID: 2cd4491e-bef3-5c11-bb51-dc161675abed

STIX ID: report--2cd4491e-bef3-5c11-bb51-dc161675abed

Feed Name: Darknet

Threat Score
75/100

Date Published: 2018-05-10

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool (with precompiled Windows binaries and source) that targets Chrome, Edge, Brave (App-Bound Encryption bypass via IElevator COM and Early Bird APC DLL injection), Opera-family and Vivaldi (DPAPI), and Firefox (NSS) to extract cookies, saved logins, OAuth refresh tokens, credit cards, autofill data, history and bookmarks into JSON. The report describes technical details, evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), usage examples, detection opportunities (unexpected process injection, IElevator calls, reads of browser SQLite DBs), and mitigation advice such as using dedicated credential managers and endpoint controls that monitor IElevator or headless browser instantiation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.