Hacking Tools, Hacker News & Cyber Security
ID: dc30f399-b973-513b-837a-0e51c459a0d0
STIX ID: report--dc30f399-b973-513b-837a-0e51c459a0d0
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks from Chrome, Edge, Brave (via an App‑Bound Encryption bypass using DLL injection and IElevator), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS). The report details how the tool spawns headless Chromium, injects a DLL using Early Bird APC to decrypt app_bound_encrypted_key, parses on‑disk SQLite/JSON stores, describes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), provides usage examples and an attack scenario, and outlines detection and mitigation opportunities for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
