Hacking Tools, Hacker News & Cyber Security
ID: 1338a924-5a55-5dc9-a3d4-d80046263f9c
STIX ID: report--1338a924-5a55-5dc9-a3d4-d80046263f9c
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation Windows tool (executable + DLL) that harvests browser‑stored credentials and session data from Chrome, Edge, Brave, Opera family, Vivaldi and Firefox. It bypasses Chrome's App‑Bound Encryption by injecting a DLL into a headless Chromium process to use the IElevator COM interface, supports DPAPI and NSS decryption for other browsers, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication, custom SQLite parser), outputs structured JSON, and is intended for red‑team/assumed‑breach testing while also demonstrating a realistic threat to enterprise SaaS and developer endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
