Hacking Tools, Hacker News & Cyber Security
ID: e9808907-762f-57c9-8a2c-c753db78da69
STIX ID: report--e9808907-762f-57c9-8a2c-c753db78da69
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit cards, autofill and browsing history from major browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, Firefox). It bypasses Chrome’s App‑Bound Encryption by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface and retrieve decryption keys, and uses file-handle duplication and other evasion techniques; output is structured JSON for red-team assessments. The report details attack scenarios, detection opportunities (process injection, IElevator calls, reads of Login Data/Cookies/Web Data), and mitigation recommendations, noting that although intended for testing, the tool’s public availability and capability enable significant cloud account takeover and lateral-movement risk on compromised developer endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
