Hacking Tools, Hacker News & Cyber Security
ID: 004931cd-5009-51c2-9daa-75c908e004e5
STIX ID: report--004931cd-5009-51c2-9daa-75c908e004e5
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests credentials and session tokens from major browsers (Chrome, Edge, Brave, Opera family, Vivaldi, and Firefox) by bypassing App-Bound Encryption (via spawning headless Chromium and using IElevator COM after Early Bird APC DLL injection) or retrieving DPAPI/NSS keys; it outputs structured JSON for red-team use and includes operational evasion features such as string obfuscation, API hashing, PPID/argument spoofing, handle duplication, and a custom SQLite parser, making it a high-risk technique for lateral movement and cloud SaaS account takeover if used by adversaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
