Hacking Tools, Hacker News & Cyber Security
ID: bc330a81-a971-5ada-bd24-a88cfc19ad9a
STIX ID: report--bc330a81-a971-5ada-bd24-a88cfc19ad9a
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool (successor to DumpChromeSecrets) that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks from Chromium-based (Chrome, Edge, Brave, Opera, Vivaldi) and Firefox browsers. It implements an App-Bound Encryption bypass for Chrome/Brave/Edge by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface and retrieve decrypted keys, uses DPAPI extraction for some Chromium forks, and NSS decryption for Firefox; output is structured JSON. The tool includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing via NtCreateUserProcess, handle duplication, custom SQLite parser) aimed at reducing EDR detection, and the report outlines detection opportunities and mitigations such as monitoring IElevator calls, headless browser instantiation, and restricting browser-stored secrets in enterprise environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
