Hacking Tools, Hacker News & Cyber Security
ID: df1a1eeb-f82d-54d2-9d8b-357cbdc7e20e
STIX ID: report--df1a1eeb-f82d-54d2-9d8b-357cbdc7e20e
Feed Name: Darknet
DumpBrowserSecrets is a precompiled Windows post-exploitation tool that harvests browser-stored credentials and session material across Chromium-based (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox browsers. The tool bypasses Chromium App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt keys, uses DPAPI/NSS handling for other browsers, and includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection). The README documents installation, usage, example attack scenarios (rapid extraction of OAuth tokens and cookies for session replay), detection opportunities (injection, IElevator calls, unexpected reads of browser SQLite files), and mitigation recommendations such as using native credential managers and EDR rules to monitor IElevator and headless browser instantiation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
