Hacking Tools, Hacker News & Cyber Security
ID: f813493d-c06e-5395-90bf-ba5d7e335182
STIX ID: report--f813493d-c06e-5395-90bf-ba5d7e335182
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation browser credential‑harvesting tool that targets Chromium‑based (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox browsers to extract passwords, cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface, handles DPAPI for some browsers and NSS for Firefox, and includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication). The write‑up covers usage, attack scenarios, detection opportunities (abnormal process injection, headless browser instantiation, IElevator calls, reads of browser SQLite DBs), and mitigation advice for enterprise defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
