Hacking Tools, Hacker News & Cyber Security
ID: 58e52191-a9be-5520-b644-4e1ef1a77b1a
STIX ID: report--58e52191-a9be-5520-b644-4e1ef1a77b1a
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests browser-stored credentials and session tokens from major Windows browsers by combining a compiled executable and a DLL that can bypass Chrome's App-Bound Encryption (via spawning a headless Chromium process and using the IElevator COM interface with Early Bird APC injection). It supports Chromium-based (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox extraction (NSS), includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is positioned for red-team/assumed-breach testing while posing a realistic risk for cloud and SaaS account takeover if used maliciously.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
