Hacking Tools, Hacker News & Cyber Security
ID: 1bc1163a-17cd-5186-a6fb-6081dd8ed764
STIX ID: report--1bc1163a-17cd-5186-a6fb-6081dd8ed764
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets modern browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox) to extract saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history. The tool pairs a compiled executable with a DLL which is injected into a headless Chromium process (via Early Bird APC) to use the IElevator COM interface and decrypt App-Bound keys, handles DPAPI and NSS decryption for other browsers, includes evasion techniques to reduce EDR detection, outputs structured JSON, and is intended for red team assumed-breach testing but poses a high-risk capability if abused by attackers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
