Hacking Tools, Hacker News & Cyber Security
ID: 7a23a028-5691-5185-b728-5883311d72c2
STIX ID: report--7a23a028-5691-5185-b728-5883311d72c2
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major Chromium‑based and Gecko browsers on Windows. It bypasses Chrome's App‑Bound Encryption (Chrome 127+) by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt keys, supports DPAPI and NSS decryption for other browsers, includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and outputs structured JSON for red‑team use; detection and mitigation guidance are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
