Hacking Tools, Hacker News & Cyber Security
ID: 9b944617-6ce4-5554-b9f6-21f41d6a1cfb
STIX ID: report--9b944617-6ce4-5554-b9f6-21f41d6a1cfb
Feed Name: Darknet
DumpBrowserSecrets is a publicly released post-exploitation tool that harvests browser-stored credentials (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill data, history, and bookmarks) from major Chromium-based browsers and Firefox on Windows. It implements an App-Bound Encryption bypass for Chrome/Brave/Edge by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface, retrieves DPAPI or NSS secrets for other browsers, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication and a custom SQLite parser). The report outlines usage, attack scenarios, detection opportunities (process injection, headless instances, IElevator calls, non-browser reads of browser databases) and mitigation advice (using dedicated credential managers and EDRs that monitor the described behaviors).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
