Hacking Tools, Hacker News & Cyber Security
ID: 32aa8d7a-2a8c-5034-bdc3-f7854e41f5af
STIX ID: report--32aa8d7a-2a8c-5034-bdc3-f7854e41f5af
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation credential-harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major Chromium-based and Firefox browsers. It bypasses Chrome's App-Bound Encryption via DLL injection into a headless Chromium process using Early Bird APC and the IElevator COM interface, handles DPAPI and NSS decryption for other browsers, and includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication). The tool outputs structured JSON, is intended for red-team/assumed-breach testing, and has clear detection and mitigation guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
