Hacking Tools, Hacker News & Cyber Security
ID: b81943bd-ebc3-5d51-b632-0ee4316cbe76
STIX ID: report--b81943bd-ebc3-5d51-b632-0ee4316cbe76
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card numbers, autofill data, and browsing history from major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It implements a DLL injection into a headless Chromium process to use the IElevator COM interface and decrypt App-Bound Encryption keys (Chrome 127+), handles DPAPI and NSS decryption for other browsers, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parsing), outputs structured JSON, and is positioned as a red-team/assumed-breach tool that could be repurposed by attackers to enable rapid lateral movement and cloud account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
