Hacking Tools, Hacker News & Cyber Security
ID: c174ad32-434d-5f9f-9f4d-09f8f26f0531
STIX ID: report--c174ad32-434d-5f9f-9f4d-09f8f26f0531
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored credentials and tokens from Chromium-based and Firefox browsers. It implements an App-Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface, retrieves DPAPI keys for Opera-family browsers, and handles Firefox using NSS decryption. The tool outputs structured JSON, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and is intended for red-team assumed-breach testing but represents a realistic credential-harvest threat for enterprise developer workstations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
