Hacking Tools, Hacker News & Cyber Security
ID: 7fc4120c-a657-516e-907b-182bc7799865
STIX ID: report--7fc4120c-a657-516e-907b-182bc7799865
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored credentials and tokens from Chrome, Edge, Brave, Opera-family browsers, Vivaldi, and Firefox; it implements an App-Bound Encryption bypass for Chromium-based browsers by spawning a headless browser, injecting a DLL via Early Bird APC, and using the IElevator COM interface to decrypt keys, then parses and decrypts on-disk SQLite/JSON stores to produce structured JSON output. The README documents usage, supported data types, evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), a realistic attack scenario, detection opportunities, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
