Hacking Tools, Hacker News & Cyber Security
ID: 9b46cf5b-d19f-5ff6-94e2-5f1e063dc288
STIX ID: report--9b46cf5b-d19f-5ff6-94e2-5f1e063dc288
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool for Windows that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from Chromium‑based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox; it bypasses Chrome App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to leverage the IElevator COM interface, and uses DPAPI/NSS methods for other browsers. The tool includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, file‑handle duplication), outputs structured JSON, and is framed for red‑team assumed‑breach testing but represents a high‑impact capability for real-world credential theft and cloud account takeover. Detection opportunities and mitigations (monitoring IElevator calls, headless browser instantiation, and moving secrets out of browsers) are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
