Hacking Tools, Hacker News & Cyber Security
ID: 55aeac37-23e0-58c8-82c6-0f7ee5265cf4
STIX ID: report--55aeac37-23e0-58c8-82c6-0f7ee5265cf4
Feed Name: Darknet
DumpBrowserSecrets is a public post-exploitation credential-harvesting tool that extracts saved logins, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from major browsers (Chrome/Edge/Brave via an App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). The tool uses DLL injection (Early Bird APC) into a headless Chromium to leverage the IElevator COM interface to decrypt app_bound_encrypted_key, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), writes output as structured JSON, and is positioned for red-team/assumed-breach testing while presenting clear detection and mitigation opportunities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
