Hacking Tools, Hacker News & Cyber Security
ID: 3f6440b3-2c8a-5712-b1fa-48888cb5c647
STIX ID: report--3f6440b3-2c8a-5712-b1fa-48888cb5c647
Feed Name: Darknet
DumpBrowserSecrets is a precompiled Windows post-exploitation tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card numbers, autofill data and browsing history from major browsers (Chrome, Edge, Brave via an App-Bound Encryption bypass using an injected DLL and IElevator; Opera/Opera GX/Vivaldi via DPAPI; Firefox via NSS decryption). The README-style report documents deployment, command-line usage, evasion techniques (Early Bird APC injection, PPID/argument spoofing, API hashing, handle duplication), expected output (JSON), an attack scenario, detection opportunities, and mitigation recommendations; it is presented as a red-team tool but is usable by malicious actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
