Hacking Tools, Hacker News & Cyber Security
ID: 16df4c28-bc72-5b4d-a5ff-cc89813807e5
STIX ID: report--16df4c28-bc72-5b4d-a5ff-cc89813807e5
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-extraction tool that targets major browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS) to retrieve passwords, cookies, OAuth refresh tokens, credit cards, autofill data, and history. It uses headless Chromium process spawning and Early Bird APC DLL injection to leverage the IElevator COM interface and decrypt app-bound keys, includes multiple evasion features, outputs structured JSON for red-team use, and presents a substantial risk to enterprise SaaS access and lateral movement if executed on compromised developer or workstation hosts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
