Hacking Tools, Hacker News & Cyber Security
ID: c97beca3-062d-540b-afab-852303243515
STIX ID: report--c97beca3-062d-540b-afab-852303243515
Feed Name: Darknet
DumpBrowserSecrets is a publicly released Windows post-exploitation tool that harvests browser-stored credentials and tokens from major browsers (Chrome/Edge/Brave via an IElevator App-Bound Encryption bypass, Opera/Opera GX/Vivaldi via DPAPI, and Firefox via NSS). It uses headless Chromium with Early Bird APC DLL injection to decrypt app_bound_encrypted_key, parses browser SQLite/JSON stores, includes multiple evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication), and outputs structured JSON — making it useful for red-team validation but also a high-value capability for adversaries seeking cloud/SaaS account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
