Hacking Tools, Hacker News & Cyber Security
ID: a2a9382c-08fc-5b79-babe-e36a44373993
STIX ID: report--a2a9382c-08fc-5b79-babe-e36a44373993
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool (publicly released) that extracts passwords, session cookies, OAuth refresh tokens, credit card numbers, autofill data, and browsing history from Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox on Windows. It bypasses Chrome’s App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface, handles DPAPI and NSS encryption models for other browsers, and includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication). The tool outputs structured JSON and is intended for red team use but has clear offensive utility for lateral movement and cloud account takeover; detection and mitigation guidance is provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
