Hacking Tools, Hacker News & Cyber Security
ID: f3f91d1a-c624-5998-9344-ab49a4f82a8a
STIX ID: report--f3f91d1a-c624-5998-9344-ab49a4f82a8a
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials and session artifacts from Windows endpoints (Chrome/Edge/Brave via an App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It uses DLL injection into a headless Chromium process (Early Bird APC + IElevator COM) to decrypt app_bound_encrypted_key, includes evasion measures (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON of recovered secrets, and is positioned for red-team assumed-breach use but carries clear offensive value for account takeover and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
