Hacking Tools, Hacker News & Cyber Security
ID: 04f37c60-ea7b-530c-a934-000ae97d9057
STIX ID: report--04f37c60-ea7b-530c-a934-000ae97d9057
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that bypasses App-Bound Encryption and other browser protections to extract saved credentials, cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox. The report details the tool's injection-based architecture (DLL injected into a headless Chromium process using Early Bird APC to leverage the IElevator COM interface), evasion techniques, output format, an attacker use-case, and detection/mitigation recommendations for enterprise defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
