Hacking Tools, Hacker News & Cyber Security
ID: 657caccb-44f1-558c-b334-1f22c5087d01
STIX ID: report--657caccb-44f1-558c-b334-1f22c5087d01
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool (with an executable and DLL) that extracts passwords, cookies, OAuth refresh tokens, credit cards, autofill and history from Chrome, Edge, Brave, Opera-family browsers and Firefox. It implements an App‑Bound Encryption bypass for Chromium (using headless process spawn + Early Bird APC DLL injection and the IElevator COM interface), DPAPI retrieval for some browsers, and NSS decryption for Firefox; includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser) and outputs structured JSON for red‑team use while also representing a high‑value technique an adversary could repurpose for account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
