Hacking Tools, Hacker News & Cyber Security
ID: 9f9f4394-d07f-541e-83c1-d2bd28499083
STIX ID: report--9f9f4394-d07f-541e-83c1-d2bd28499083
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, history and bookmarks from Chromium‑based (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox browsers. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface and retrieve decrypted keys, supports DPAPI and NSS decryption for other browsers, outputs structured JSON, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser); the report also describes attack scenarios, detection opportunities, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
