Hacking Tools, Hacker News & Cyber Security
ID: b501c655-5787-5d71-a98d-3f4b52cc809a
STIX ID: report--b501c655-5787-5d71-a98d-3f4b52cc809a
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post‑exploitation tool that harvests browser‑stored credentials and session tokens from major Windows browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). The tool uses headless Chromium process spawning and Early Bird APC DLL injection to call the IElevator COM interface and decrypt app_bound_encrypted_key, then reads and decrypts browser SQLite/JSON stores to output structured JSON containing cookies, OAuth refresh tokens, saved logins, credit cards, autofill and history; it includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication) and is presented as a red team utility while being relevant to real-world credential theft scenarios.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
