Hacking Tools, Hacker News & Cyber Security
ID: 380d2a7a-fd4d-52b5-a5c7-eeee9a8a2f51
STIX ID: report--380d2a7a-fd4d-52b5-a5c7-eeee9a8a2f51
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool for Windows that extracts passwords, cookies, OAuth refresh tokens, credit cards, autofill data and history from Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt encryption keys, uses DPAPI/NSS handling where appropriate, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON for red-team use, and is positioned as a capability to evaluate credential exposure and endpoint defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
