Hacking Tools, Hacker News & Cyber Security
ID: f03022a0-b3b2-5f48-906e-41286e99cff8
STIX ID: report--f03022a0-b3b2-5f48-906e-41286e99cff8
Feed Name: Darknet
DumpBrowserSecrets is a technical review of a Windows post‑exploitation credential‑harvesting tool that targets Chromium‑based and Firefox browsers to extract saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and history. It documents the tool's App‑Bound Encryption bypass (using a headless Chromium process, Early Bird APC DLL injection and the IElevator COM interface), DPAPI and NSS decryption approaches, operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, file‑handle duplication), example attack scenarios, and detection/mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
