Hacking Tools, Hacker News & Cyber Security
ID: 36b8d5e2-ceca-5b4a-aabe-194a0c4b8c5b
STIX ID: report--36b8d5e2-ceca-5b4a-aabe-194a0c4b8c5b
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored credentials and session material (saved passwords, cookies, OAuth refresh tokens, credit cards, autofill, history) across major Chromium-based browsers and Firefox. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface, handles DPAPI and NSS encryption models, includes operational evasion (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is positioned for red-team/assumed-breach testing while also representing a high-risk credential-extraction capability for real-world attackers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
