Hacking Tools, Hacker News & Cyber Security
ID: 87ad46d0-6480-51c6-abe3-b71852392e39
STIX ID: report--87ad46d0-6480-51c6-abe3-b71852392e39
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox. The report details how it bypasses Chrome's App‑Bound Encryption by launching a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface, handles DPAPI and NSS encryption models, includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and provides detection and mitigation advice for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
