Hacking Tools, Hacker News & Cyber Security
ID: 27050765-b55b-55a3-a4fb-96b4633a6165
STIX ID: report--27050765-b55b-55a3-a4fb-96b4633a6165
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation browser credential-harvesting tool that targets Chrome, Edge, Brave (App-Bound Encryption), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS) to extract passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and history. The report explains its App-Bound Encryption bypass (spawning headless Chromium and injecting a DLL via Early Bird APC to use the IElevator COM interface), operational evasion techniques, output format, red-team relevance, detection opportunities, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
