Hacking Tools, Hacker News & Cyber Security
ID: 90057ef4-ac5e-5a67-8e87-bbdd218c21f6
STIX ID: report--90057ef4-ac5e-5a67-8e87-bbdd218c21f6
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post‑exploitation tool that extracts credentials and session tokens from major Windows browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface, retrieves DPAPI or NSS secrets for other browsers, and outputs structured JSON of recovered cookies, OAuth refresh tokens, saved logins, credit cards, autofill, and history. The tool includes multiple evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser) intended to reduce EDR detection and is positioned for red-team assumed‑breach testing but could be repurposed by adversaries for cloud account takeover and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
