Hacking Tools, Hacker News & Cyber Security
ID: 5073a027-afc8-54df-bb2d-26e1d7cc80cc
STIX ID: report--5073a027-afc8-54df-bb2d-26e1d7cc80cc
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored secrets (saved credentials, session cookies, OAuth refresh tokens, credit cards, autofill, and history) across major Chromium-based and Firefox browsers. It implements an App-Bound Encryption bypass for Chrome/Brave/Edge by spawning a headless Chromium process and injecting a DLL (Early Bird APC) to call the IElevator COM interface, handles DPAPI-based browsers and NSS-based Firefox logins, includes operational evasion (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and outputs structured JSON for rapid credential theft and session replay; the report also provides detection and mitigation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
