logo

JTR (Password Cracking) – John the Ripper 1.7 Released – FINALLY

ID: 6551b9a1-51c1-5fd3-803e-828379259d83

STIX ID: report--6551b9a1-51c1-5fd3-803e-828379259d83

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-03-11

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a post‑exploitation credential extraction tool that targets Chromium- and Gecko-based browsers on Windows to recover saved passwords, session cookies, OAuth refresh tokens, credit card data and other browser-stored secrets; it bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process, injecting a DLL via Early Bird APC to use the IElevator COM interface, and returns decrypted keys to the main executable for local decryption. The report describes supported browsers and encryption models, operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), usage examples, an attack scenario demonstrating rapid credential theft for lateral/cloud account takeover, and detection/mitigation recommendations for EDR and policy controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.