Hacking Tools, Hacker News & Cyber Security
ID: f9b6d953-9598-5b05-937e-ea1426f23897
STIX ID: report--f9b6d953-9598-5b05-937e-ea1426f23897
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post‑exploitation tool for Windows that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It implements an App‑Bound Encryption bypass for Chromium-based browsers by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface to decrypt keys, handles DPAPI and NSS decryption for other browsers, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, custom SQLite parsing), outputs structured JSON, and is positioned for red-team use but poses a significant abuse risk in real intrusions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
