Hacking Tools, Hacker News & Cyber Security
ID: 0a3ccb9b-aa91-506e-bafa-5eff354c5b8f
STIX ID: report--0a3ccb9b-aa91-506e-bafa-5eff354c5b8f
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting utility targeting Chromium and Gecko browsers that bypasses Chrome's App‑Bound Encryption by injecting a DLL into a headless Chromium process (via Early Bird APC) to use the IElevator COM interface, and also handles DPAPI and NSS decryption for other browsers; it extracts cookies, saved logins, OAuth refresh tokens, credit card data, autofill entries and history, outputs structured JSON for red‑team use, and includes multiple operational evasion techniques while the report outlines detection and mitigation approaches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
