Hacking Tools, Hacker News & Cyber Security
ID: b9c1b4c4-f617-54ec-9ea1-faf1e8d9ec30
STIX ID: report--b9c1b4c4-f617-54ec-9ea1-faf1e8d9ec30
Feed Name: Darknet
DumpBrowserSecrets is a public post-exploitation tool designed to extract credentials and session data from major Windows browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium instance and injecting a DLL via Early Bird APC to call the IElevator COM interface, retrieves DPAPI or NSS secrets as applicable, and outputs structured JSON of cookies, saved logins, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks. The tool includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication) and is intended for red-team assumed-breach exercises but represents a high-risk credential theft capability if abused by adversaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
