Hacking Tools, Hacker News & Cyber Security
ID: a4f81fd5-fbc6-5ffc-99f2-f2f50438717c
STIX ID: report--a4f81fd5-fbc6-5ffc-99f2-f2f50438717c
Feed Name: Darknet
DumpBrowserSecrets is a Windows post‑exploitation credential‑harvesting tool (successor to DumpChromeSecrets) that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from Chromium‑based and Firefox browsers. The tool implements an App‑Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt browser keys; Opera/Vivaldi use DPAPI retrieval and Firefox uses NSS decryption. It includes operational evasion (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser) and outputs structured JSON for red‑team use; the report covers attack scenarios, detection opportunities, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
