Hacking Tools, Hacker News & Cyber Security
ID: 55e71397-8065-5b66-860c-f3dbb5e4ca4b
STIX ID: report--55e71397-8065-5b66-860c-f3dbb5e4ca4b
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post‑exploitation tool that harvests credentials and session material from major Windows browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, Firefox). It bypasses Chrome App‑Bound Encryption by injecting a DLL into a headless Chromium process to call the IElevator COM interface, retrieves DPAPI or NSS secrets where applicable, and outputs structured JSON. The report covers supported browsers and data types, operational evasion (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection, custom SQLite parser), an attack scenario demonstrating rapid token/credential collection for cloud takeover, and detection/mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
