Hacking Tools, Hacker News & Cyber Security
ID: fa8d6908-4ed2-5682-9e0d-dd1414310c37
STIX ID: report--fa8d6908-4ed2-5682-9e0d-dd1414310c37
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets Chrome, Edge, Brave (App‑Bound Encryption), Opera/Vivaldi family (DPAPI), and Firefox (NSS) to extract saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill, history and bookmarks from Windows hosts. It bypasses Chrome's App‑Bound Encryption (Chrome 127+) by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface, returns decrypted keys over a named pipe, parses browser SQLite/JSON stores, and writes structured JSON output; the tool includes operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication) and is presented as a red-team/assumed-breach capability with high potential for cloud account takeover and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
