Hacking Tools, Hacker News & Cyber Security
ID: 760bf11b-fbcc-510e-90da-04ef909045e7
STIX ID: report--760bf11b-fbcc-510e-90da-04ef909045e7
Feed Name: Darknet
DumpBrowserSecrets is a precompiled Windows post‑exploitation tool that harvests saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from Chromium-based browsers (Chrome, Edge, Brave, Opera family, Vivaldi) and Firefox. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface to decrypt the app_bound_encrypted_key, handles DPAPI and NSS decryption for other browsers, includes multiple evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON, and is presented for red‑team/assumed‑breach testing while having clear potential for misuse to enable cloud account takeover and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
