Hacking Tools, Hacker News & Cyber Security
ID: 7b5c7a66-7f20-5f33-bb90-c6999f796129
STIX ID: report--7b5c7a66-7f20-5f33-bb90-c6999f796129
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from Chromium‑based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. The tool bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt the app_bound_encrypted_key, uses DPAPI or NSS handling where appropriate, and includes multiple evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parsing). The report documents technical operation, supported browsers, example attack scenarios, detection opportunities, and mitigation recommendations for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
