Hacking Tools, Hacker News & Cyber Security
ID: 13390bba-5954-5661-940c-1610e5ab2aa9
STIX ID: report--13390bba-5954-5661-940c-1610e5ab2aa9
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post‑exploitation tool that harvests browser‑stored credentials and session artifacts from major Windows browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It implements an IElevator COM-based App‑Bound Encryption bypass for Chromium-based browsers by spawning a headless browser and performing Early Bird APC DLL injection to decrypt keys, uses DPAPI and NSS handling for other browsers, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-lock bypass). The tool outputs structured JSON of recovered secrets (cookies, saved logins, OAuth refresh tokens, credit cards, autofill, history) and is intended for red‑team/assumed‑breach testing, while also representing a credible threat vector for cloud account takeover and lateral movement if abused.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
