Hacking Tools, Hacker News & Cyber Security
ID: fcd35d76-8077-54b5-99fd-ca6e43799f71
STIX ID: report--fcd35d76-8077-54b5-99fd-ca6e43799f71
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card details, autofill data and browsing history from major browsers (Chrome, Edge, Brave, Opera/Opera GX, Vivaldi, Firefox). It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt the app_bound_encrypted_key; it handles DPAPI and NSS-based encryption for other browsers, writes structured JSON output, and includes multiple operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser). The report highlights high impact risks for compromised developer endpoints (cloud account takeover, lateral movement, persistent SaaS access), detection opportunities (injection, IElevator calls, reads of browser SQLite files) and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
