Hacking Tools, Hacker News & Cyber Security
ID: a8ef7b5e-d579-58a1-9137-761d714d3000
STIX ID: report--a8ef7b5e-d579-58a1-9137-761d714d3000
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post‑exploitation tool that extracts credentials and session tokens from major Windows browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox). It bypasses Chrome's App‑Bound Encryption by injecting a DLL into a spawned headless Chromium process to call the IElevator COM interface, retrieves DPAPI and NSS secrets for other browsers, and writes structured JSON containing cookies, saved logins, OAuth refresh tokens, credit cards, autofill data, history, and bookmarks; the tool includes several evasion features (string obfuscation, API hashing, PPID/argument spoofing, file‑handle duplication) and is intended for red team/assumed‑breach use but presents a realistic threat to enterprise credential hygiene.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
