Hacking Tools, Hacker News & Cyber Security
ID: 22b5c021-ac73-5d97-97ac-07c13b4a294c
STIX ID: report--22b5c021-ac73-5d97-97ac-07c13b4a294c
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential harvesting tool that targets Chromium‑based (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox browsers to extract saved passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, and history. It implements an App‑Bound Encryption bypass for Chrome 127+ by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface, includes DPAPI and NSS handling for other browsers, and contains operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, file handle duplication) aimed at red teams and threat actors; output is structured JSON intended for rapid credential replay or validation, and the report outlines detection and mitigation opportunities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
