Hacking Tools, Hacker News & Cyber Security
ID: f1ef3277-9148-5473-a0eb-d504b20324b4
STIX ID: report--f1ef3277-9148-5473-a0eb-d504b20324b4
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored secrets (saved logins, session cookies, OAuth tokens, credit cards, autofill and history) from major Chromium-based and Firefox browsers. It bypasses Chrome’s App-Bound Encryption (Chrome 127+) by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface, retrieves DPAPI or NSS keys where applicable, and outputs structured JSON. The tool includes multiple operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser) and is positioned for red-team assumed-breach testing; the report also describes detection opportunities and mitigation guidance (monitor IElevator calls, flag unexpected headless browsers, use dedicated credential managers).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
