logo

Chinese Police Shut Down ‘Black Hawk Safety Net’ Hacking School

ID: 4ac467e5-0c0c-56d0-923d-a3927aa0bb74

STIX ID: report--4ac467e5-0c0c-56d0-923d-a3927aa0bb74

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-02-09

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major browsers (Chrome, Edge, Brave, Opera family, Vivaldi, and Firefox). It bypasses Chrome’s App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface (using Early Bird APC injection), handles DPAPI and NSS models for other browsers, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parsing), outputs structured JSON, and is presented for red‑team use while clearly usable for malicious credential theft and lateral/cloud account takeover.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.