Hacking Tools, Hacker News & Cyber Security
ID: 45769250-13f2-535b-9dfd-515da2881e71
STIX ID: report--45769250-13f2-535b-9dfd-515da2881e71
Feed Name: Darknet
DumpBrowserSecrets is a publicly released post‑exploitation tool that harvests browser‑stored secrets from Chrome, Edge, Brave (App‑Bound Encryption bypass), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS). It uses a compiled executable plus a DLL injected into a headless Chromium process to decrypt app_bound_encrypted_key via the IElevator COM interface, extracts SQLite/JSON data (logins, cookies, OAuth tokens, cards, history), and includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, file‑handle duplication). The report discusses use cases for red teams, detection opportunities (injection, IElevator calls, non‑browser reads of Login Data/Cookies/Web Data), and mitigation recommendations such as moving secrets out of browsers to dedicated credential managers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
