Hacking Tools, Hacker News & Cyber Security
ID: 2e17d24c-6dad-53c0-876f-3e6bfcfbbf2b
STIX ID: report--2e17d24c-6dad-53c0-876f-3e6bfcfbbf2b
Feed Name: Darknet
DumpBrowserSecrets is a Windows post‑exploitation tool (published as a precompiled executable + DLL) designed to extract saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, history and bookmarks from Chromium-based and Firefox browsers. It bypasses Chrome's App‑Bound Encryption (Chrome 127+) by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface (Early Bird APC injection), retrieves DPAPI keys for some Chromium forks, and handles Firefox NSS decryption directly. The tool includes operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON, and is presented as a red-team/assumed-breach testing utility while being clearly usable for malicious credential theft; the report also includes detection and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
