Hacking Tools, Hacker News & Cyber Security
ID: 334bdbc1-0a19-5876-a452-f6469c110fa3
STIX ID: report--334bdbc1-0a19-5876-a452-f6469c110fa3
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that targets Chrome, Edge, Brave (App‑Bound Encryption), Opera/Opera GX/Vivaldi (DPAPI) and Firefox (NSS) to extract saved credentials, cookies, OAuth tokens, credit cards and history. The tool bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL (via Early Bird APC) to call the IElevator COM interface, returns decrypted keys over a pipe, and parses on‑disk SQLite/JSON stores; it includes multiple operational evasion techniques and outputs structured JSON useful for red‑team or abuse scenarios, while the report also outlines detection and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
