Hacking Tools, Hacker News & Cyber Security
ID: f428d984-6f64-5f37-a49a-d6d4076376d0
STIX ID: report--f428d984-6f64-5f37-a49a-d6d4076376d0
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests saved credentials, session cookies, OAuth tokens, credit card data, autofill entries, and browsing history from major Windows browsers. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface, supports DPAPI and NSS decryption for other browsers, includes multiple operational evasion techniques, outputs structured JSON for red-team use, and the report describes attack scenarios, detection points (e.g., IElevator calls, unexpected reads of browser SQLite DBs, headless browser instantiation), and mitigation recommendations such as using separate native password managers and EDR rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
