Hacking Tools, Hacker News & Cyber Security
ID: a258e398-f3c1-5ded-8cb2-154249a2a067
STIX ID: report--a258e398-f3c1-5ded-8cb2-154249a2a067
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool (and successor to DumpChromeSecrets) that extracts passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from Chromium‑based and Gecko‑based browsers on Windows. It bypasses Chrome’s App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface, supports DPAPI and NSS decryption for other browsers, includes operational evasion features to reduce EDR detection, outputs structured JSON, and is positioned as a red‑team tool for assumed‑breach exercises but poses a significant credential theft risk if weaponized by adversaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
