Hacking Tools, Hacker News & Cyber Security
ID: a40153ca-301d-5be0-8ded-4ef8eecb6d5b
STIX ID: report--a40153ca-301d-5be0-8ded-4ef8eecb6d5b
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool (successor to DumpChromeSecrets) that extracts saved passwords, cookies, OAuth refresh tokens, credit card data, autofill, and history from major Chromium-based and Firefox browsers on Windows; it bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface, retrieves DPAPI keys for other Chromium forks, and handles Firefox logins via NSS decryption. The tool includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing via NtCreateUserProcess, handle duplication, and a custom SQLite parser), outputs structured JSON, and is presented as a red-team/assumed-breach testing utility with detection and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
