Hacking Tools, Hacker News & Cyber Security
ID: 7f4ee284-5a67-5208-be5f-2ebeb4564403
STIX ID: report--7f4ee284-5a67-5208-be5f-2ebeb4564403
Feed Name: Darknet
DumpBrowserSecrets is a pre-compiled Windows post-exploitation tool that extracts browser-stored credentials and session tokens from major Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It bypasses App-Bound Encryption in modern Chromium builds by spawning a headless Chromium process and injecting a DLL (Early Bird APC) to call the IElevator COM interface, retrieves DPAPI/NSS keys where applicable, parses on-disk SQLite/JSON stores, and outputs structured JSON. The tool includes operational evasion (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser) making it relevant for red-team testing and a potentially high-impact capability for real attackers seeking cloud account takeover or lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
