Hacking Tools, Hacker News & Cyber Security
ID: 2cb26d20-245d-5682-91f7-8ed176b5d066
STIX ID: report--2cb26d20-245d-5682-91f7-8ed176b5d066
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major Chromium-based and Firefox browsers on Windows. It bypasses App-Bound Encryption in Chrome/Edge/Brave by injecting a DLL into a headless Chromium process to use the IElevator COM interface, retrieves DPAPI or NSS-protected keys for other browsers, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, and a custom SQLite parser). The tool is targeted at red teams for assumed-breach testing but represents a realistic offensive capability that enables rapid session replay and cloud account takeover if used by malicious actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
