Hacking Tools, Hacker News & Cyber Security
ID: 07d0b281-7565-585d-aa01-3ebbcfd33cbc
STIX ID: report--07d0b281-7565-585d-aa01-3ebbcfd33cbc
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser‑stored credentials and session tokens from major Chromium‑based browsers and Firefox. It implements an App‑Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt the app_bound_encrypted_key, retrieves DPAPI keys for some browsers, and handles Firefox NSS decryption directly. The tool outputs structured JSON, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parsing), and is positioned for red team/useful to attackers because recovered cookies and OAuth refresh tokens enable cloud account takeover and lateral movement; the report also outlines detection and mitigation opportunities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
