Hacking Tools, Hacker News & Cyber Security
ID: 2eb65a7f-94f5-503d-a792-0a937cade166
STIX ID: report--2eb65a7f-94f5-503d-a792-0a937cade166
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox; it bypasses Chrome's App-Bound Encryption (Chrome 127+) by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface, and then decrypts on-disk browser data locally. The report includes technical implementation details, evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), usage examples, an attack scenario demonstrating rapid credential capture, and detection and mitigation guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
