Hacking Tools, Hacker News & Cyber Security
ID: 04641a46-e1c9-5cef-832e-9137b7182e3f
STIX ID: report--04641a46-e1c9-5cef-832e-9137b7182e3f
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests browser-stored credentials and session tokens from major Windows browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It bypasses App-Bound Encryption in Chromium-based browsers by spawning a headless Chromium process and injecting a DLL via Early Bird APC to leverage the IElevator COM interface, retrieves DPAPI keys where applicable, parses on-disk SQLite/JSON stores, and writes structured JSON output; the tool includes several evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser) and is positioned for red-team assumed-breach testing while also representing a high-value capability for credential theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
