Hacking Tools, Hacker News & Cyber Security
ID: e5ae53e5-9f82-5506-b497-e111f54e8177
STIX ID: report--e5ae53e5-9f82-5506-b497-e111f54e8177
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post‑exploitation tool that harvests browser‑stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill data and history) from major Chromium- and Gecko-based browsers on Windows. It implements an App‑Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and injecting a DLL that uses the IElevator COM interface to decrypt keys, handles DPAPI and NSS models for other browsers, includes operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication), outputs structured JSON, and is positioned for red-team/assumed-breach testing while also representing a viable capability for malicious actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
