JTR (Password Cracking) – John the Ripper 1.7 Released – FINALLY
ID: 6551b9a1-51c1-5fd3-803e-828379259d83
STIX ID: report--6551b9a1-51c1-5fd3-803e-828379259d83
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential extraction tool that targets Chromium- and Gecko-based browsers on Windows to recover saved passwords, session cookies, OAuth refresh tokens, credit card data and other browser-stored secrets; it bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process, injecting a DLL via Early Bird APC to use the IElevator COM interface, and returns decrypted keys to the main executable for local decryption. The report describes supported browsers and encryption models, operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), usage examples, an attack scenario demonstrating rapid credential theft for lateral/cloud account takeover, and detection/mitigation recommendations for EDR and policy controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
