Hacking Tools, Hacker News & Cyber Security
ID: 0023e071-79e9-51cc-bf51-02366eafd8f4
STIX ID: report--0023e071-79e9-51cc-bf51-02366eafd8f4
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials and session tokens from major Windows browsers; it bypasses Chrome’s App-Bound Encryption by spawning a headless Chromium process, injecting a DLL via Early Bird APC to use the IElevator COM interface, and decrypting the app_bound_encrypted_key, while using DPAPI/NSS handling for other browsers. The tool outputs structured JSON of cookies, OAuth tokens, saved logins, credit cards, autofill data and history, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), completes extraction rapidly, and is intended for red-team testing but represents a high-risk capability for real-world credential theft and cloud account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
