Hacking Tools, Hacker News & Cyber Security
ID: 652f396e-df3b-5e6f-a728-0b8acc1473fb
STIX ID: report--652f396e-df3b-5e6f-a728-0b8acc1473fb
Feed Name: Darknet
DumpBrowserSecrets is a Windows post‑exploitation credential‑harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, and other browser-stored secrets from Chromium-based (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox browsers. It includes an App‑Bound Encryption bypass for modern Chromium builds by spawning a headless browser and using in‑process DLL injection with the IElevator COM interface, handles DPAPI and NSS decryption models, and implements operational evasion (string obfuscation, API hashing, PPID/argument spoofing, handle duplication). The report outlines usage, attack scenarios demonstrating rapid credential collection enabling cloud account takeover and lateral movement, and detection/mitigation guidance such as monitoring IElevator calls, headless browser instantiation, and moving secrets to native password managers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
