Hacking Tools, Hacker News & Cyber Security
ID: 2e382890-9bca-50d0-87d9-3b32e79ecb83
STIX ID: report--2e382890-9bca-50d0-87d9-3b32e79ecb83
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation tool designed to harvest credentials and session tokens from major Windows browsers (Chrome, Edge, Brave, Opera family, Vivaldi, and Firefox). It implements an App-Bound Encryption bypass for Chromium-based browsers by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt the app_bound_encrypted_key, and then parses and decrypts on-disk browser data (or uses DPAPI/NSS where applicable). The tool outputs structured JSON, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and is positioned for red-team/assumed-breach use to demonstrate credential exposure and test endpoint defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
