Hacking Tools, Hacker News & Cyber Security
ID: c080c330-2236-5881-b944-831f2cb84784
STIX ID: report--c080c330-2236-5881-b944-831f2cb84784
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored secrets (saved logins, cookies, OAuth refresh tokens, credit cards, autofill, history, bookmarks) from Chrome/Edge/Brave (via an App-Bound Encryption bypass using a headless Chromium + DLL injected via Early Bird APC and the IElevator COM interface), Opera/Opera GX/Vivaldi (DPAPI-based), and Firefox (NSS-based). The tool outputs structured JSON, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication, custom SQLite parsing), and is positioned for red-team assumed-breach use but could be repurposed by adversaries; the report also outlines detection opportunities and mitigations such as monitoring IElevator calls, headless browser instantiation, and restricting browser-stored credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
