Hacking Tools, Hacker News & Cyber Security
ID: cb566a1d-8c10-57e3-b114-3cb30b6d24e7
STIX ID: report--cb566a1d-8c10-57e3-b114-3cb30b6d24e7
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that targets Chromium‑based and Gecko‑based browsers to extract saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface, handles DPAPI and NSS decryption for other browsers, and includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication). The tool is designed for assumed‑breach/red team use and can produce structured JSON output with recovered secrets that enable lateral movement and cloud account takeover; detection opportunities include anomalous headless browser instantiation, unexpected process injection, reads of browser SQLite DBs by non-browser processes, and IElevator COM calls from non-browser contexts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
