Hacking Tools, Hacker News & Cyber Security
ID: c42c0926-0a0a-5a0a-9490-4965b89cd74a
STIX ID: report--c42c0926-0a0a-5a0a-9490-4965b89cd74a
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation tool that harvests browser-stored credentials and session tokens from Chrome, Edge, Brave, Opera-family browsers, Vivaldi, and Firefox. It bypasses App-Bound Encryption in Chromium browsers by spawning a headless process and injecting a DLL to use the IElevator COM interface to decrypt keys, and uses DPAPI or NSS handling where applicable; outputs structured JSON, includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection), and is intended for red-team assumed-breach testing but poses a high risk if used by malicious actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
