Hacking Tools, Hacker News & Cyber Security
ID: 5dd7279f-48b9-563b-a0a2-54d0487d55a0
STIX ID: report--5dd7279f-48b9-563b-a0a2-54d0487d55a0
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post‑exploitation tool that extracts browser‑stored credentials and session tokens from major Chromium- and Gecko-based browsers on Windows; it implements an App‑Bound Encryption bypass for Chrome/Edge/Brave via spawning a headless Chromium instance and DLL injection (Early Bird APC) to use the IElevator COM interface, handles DPAPI for Opera/Vivaldi, and uses NSS decryption for Firefox. The report covers extracted data types, operational evasion features, usage examples, detection opportunities (process injection, headless browser instantiation, IElevator calls, reads of browser SQLite DBs), and mitigation recommendations such as moving secrets to native password managers and EDR detection of IElevator/headless behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
