Hacking Tools, Hacker News & Cyber Security
ID: 95fefab9-6c7f-59b1-85ba-5da107ab93ee
STIX ID: report--95fefab9-6c7f-59b1-85ba-5da107ab93ee
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests browser-stored credentials and session artifacts across major Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It implements an App-Bound Encryption bypass for Chrome 127+ by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface, retrieves DPAPI or NSS keys as appropriate, and writes structured JSON output containing passwords, cookies, OAuth refresh tokens, credit cards, autofill data and history. The report covers operational evasion (string/API obfuscation, Early Bird APC injection, PPID/argument spoofing, file-handle duplication), a red-team attack scenario, detection opportunities (monitor IElevator usage, unexpected process injection, unauthorized reads of browser SQLite DBs), and mitigations (use of external password managers, EDR rules).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
