Hacking Tools, Hacker News & Cyber Security
ID: 396e5cf4-1b13-5893-9c06-5c00810adf1b
STIX ID: report--396e5cf4-1b13-5893-9c06-5c00810adf1b
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that targets Chrome, Edge, Brave (via App‑Bound Encryption bypass), Opera/ Vivaldi/Opera GX (DPAPI), and Firefox (NSS) to extract saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and history. It uses Early Bird APC DLL injection into a headless Chromium process to call the IElevator COM interface and decrypt app_bound_encrypted_key, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), writes structured JSON output, and is positioned for red team/assumed‑breach testing but presents clear risk if abused by adversaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
