Hacking Tools, Hacker News & Cyber Security
ID: e17ffb04-2b00-50fd-b416-d8a392068d79
STIX ID: report--e17ffb04-2b00-50fd-b416-d8a392068d79
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation credential-harvesting tool that targets Chromium-based and Firefox browsers to extract saved passwords, session cookies, OAuth refresh tokens, credit card and autofill data, and browsing history. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt the app_bound_encrypted_key; it also retrieves DPAPI keys for Opera-family browsers and uses NSS decryption for Firefox. Designed for red-team use, the tool outputs structured JSON, includes multiple EDR-evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, file handle duplication, custom SQLite parsing), and the report includes usage examples, detection vectors, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
