Hacking Tools, Hacker News & Cyber Security
ID: ee55cb24-7a4d-5a94-96b2-44fcca00e73c
STIX ID: report--ee55cb24-7a4d-5a94-96b2-44fcca00e73c
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card numbers, autofill data, and browsing history from major Chromium-based and Firefox browsers. It bypasses Chrome's App‑Bound Encryption (Chrome 127+) by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface to decrypt the app_bound_encrypted_key; for DPAPI and NSS-backed browsers it retrieves DPAPI keys or decrypts with NSS respectively. The tool includes operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection, custom SQLite parser), outputs structured JSON, and is presented for red-team assumed-breach testing but could enable rapid lateral movement and cloud/SaaS account takeover if used by adversaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
