Hacking Tools, Hacker News & Cyber Security
ID: bfdd44bf-b1f7-56b4-a513-40c712c38433
STIX ID: report--bfdd44bf-b1f7-56b4-a513-40c712c38433
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post‑exploitation tool that rapidly extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from major Windows browsers by bypassing Chrome’s App‑Bound Encryption (via spawning a headless Chromium process, Early Bird APC DLL injection and the IElevator COM interface), handling DPAPI for Opera/Vivaldi and NSS for Firefox; it includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON for red‑team use, and poses a high risk for cloud account takeover and lateral movement if abused.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
