Hacking Tools, Hacker News & Cyber Security
ID: 5fb8db37-8dd7-5926-b22e-bb929a14e0c0
STIX ID: report--5fb8db37-8dd7-5926-b22e-bb929a14e0c0
Feed Name: Darknet
DumpBrowserSecrets is a Windows post‑exploitation tool that harvests browser-stored credentials and session tokens from Chromium-based and Firefox browsers by combining a compiled executable with a DLL that performs Early Bird APC injection into a headless Chromium process to use the IElevator COM interface and decrypt App-Bound Encryption keys; it also handles DPAPI and NSS decryption. The report covers extracted data types, evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication), usage and attack scenarios, detection opportunities, and mitigation recommendations, and notes the tool is intended for red-team/assumed-breach testing but poses a realistic threat if misused.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
