Hacking Tools, Hacker News & Cyber Security
ID: 6ca9ab37-7489-54a3-a487-ac7e59014164
STIX ID: report--6ca9ab37-7489-54a3-a487-ac7e59014164
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, history and bookmarks from major Chromium- and Gecko-based browsers on Windows. It implements an App-Bound Encryption bypass for Chrome/Brave/Edge by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface, and returning decrypted keys to decrypt on-disk SQLite/JSON stores; it also handles DPAPI and NSS models for other browsers, includes runtime evasion features, and outputs structured JSON to aid red-team operations and attacker credential reuse. Detection opportunities and mitigations are discussed but the tool's public availability and evasion primitives make it a high-risk capability for credential theft and cloud account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
