Hacking Tools, Hacker News & Cyber Security
ID: 2fca627b-744b-5d37-8445-97a63e612b1e
STIX ID: report--2fca627b-744b-5d37-8445-97a63e612b1e
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that extracts browser-stored credentials and session artifacts from major browsers (Chrome, Edge, Brave, Opera family, Vivaldi, Firefox). It implements an App-Bound Encryption bypass for Chromium-based browsers by spawning a headless browser and injecting a DLL via Early Bird APC to leverage the IElevator COM interface, and handles DPAPI and NSS decryption for other browsers. The tool outputs structured JSON of recovered secrets (cookies, OAuth refresh tokens, saved logins, credit cards, autofill data, history) and includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), making it useful for red teams and potentially for malicious actors seeking rapid cloud account takeover and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
