Hacking Tools, Hacker News & Cyber Security
ID: 0e1245a1-2ea3-567a-b946-991cfff28dff
STIX ID: report--0e1245a1-2ea3-567a-b946-991cfff28dff
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that targets Chrome, Edge, Brave (App‑Bound Encryption), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS) to extract saved passwords, cookies, OAuth tokens, credit cards, autofill data and history. It uses a compiled executable plus a DLL injected into a headless Chromium process (Early Bird APC injection) to leverage the IElevator COM interface and decrypt app_bound_encrypted_key, implements evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is presented as a red‑team tool useful for testing endpoint controls and realistic credential blast radius.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
