RDP Security Tool For Hacking Remote Desktop Protocol
ID: 94a16288-ba8b-5fe9-b612-09198bf604ef
STIX ID: report--94a16288-ba8b-5fe9-b612-09198bf604ef
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool for Windows that harvests browser-stored credentials (cookies, saved logins, OAuth refresh tokens, credit cards, autofill and history) across Chromium-based browsers and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface, retrieves DPAPI or NSS-protected keys as needed, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), and writes structured JSON output for use in lateral movement or cloud account takeover testing. The report details usage, supported browsers, detection indicators (injection, headless instantiation, IElevator calls, database reads), and mitigation recommendations such as using external credential managers and EDR monitoring of the discussed behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
