Hacking Tools, Hacker News & Cyber Security
ID: b24cf519-8e3c-5c67-9825-35e52700beff
STIX ID: report--b24cf519-8e3c-5c67-9825-35e52700beff
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, and history from Chromium-based and Gecko-based browsers on Windows. It bypasses Chrome’s App-Bound Encryption by injecting a DLL into a headless Chromium process to call the IElevator COM interface, retrieves DPAPI keys for some Chromium forks, handles Firefox NSS decryption directly, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication, and a custom SQLite parser). The tool is aimed at red team/assumed-breach testing but demonstrates a high-risk technique for lateral movement and cloud account takeover if used by malicious actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
