Oracle Releases a Default Password Scanner
ID: f78759ab-cff4-5e29-ae74-56898b39413e
STIX ID: report--f78759ab-cff4-5e29-ae74-56898b39413e
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials (saved logins, session cookies, OAuth refresh tokens, credit card data, autofill and history) from Chromium-based browsers and Firefox on Windows. The report details how the tool bypasses Chrome's App-Bound Encryption by injecting a DLL into a headless Chromium process to use the IElevator COM interface, retrieves DPAPI/NSS keys for other browsers, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication), and outputs structured JSON for red-team use while providing detection and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
