Hacking Tools, Hacker News & Cyber Security
ID: a6a640ca-c713-5c17-8902-24f7f31a9c0d
STIX ID: report--a6a640ca-c713-5c17-8902-24f7f31a9c0d
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill data, history, and bookmarks) from Chromium-based and Gecko-based browsers on Windows. It bypasses Chrome’s App-Bound Encryption by spawning a headless Chromium process, injecting a DLL via Early Bird APC to use the IElevator COM interface, and returns decrypted keys to parse and decrypt on-disk SQLite/JSON stores; it also handles DPAPI and NSS-protected stores, outputs structured JSON, and includes evasion features intended to reduce EDR detection—making it a realistic high-impact tool for lateral movement and cloud account takeover during assumed-breach engagements.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
