Hacking Tools, Hacker News & Cyber Security
ID: a25a522d-e05d-5a31-9814-f22afe50229e
STIX ID: report--a25a522d-e05d-5a31-9814-f22afe50229e
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation browser credential‑harvesting tool that extracts saved passwords, cookies, OAuth refresh tokens, credit card numbers, autofill data and history from Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox on Windows. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface, uses DPAPI or NSS decryption for other browsers, and includes multiple evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication). Intended for red‑team assumed‑breach testing, the tool nonetheless represents a high‑impact capability for credential theft and cloud account takeover if used by adversaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
