Hacking Tools, Hacker News & Cyber Security
ID: 36b43b69-1e87-51a7-9a39-0a1daac289c1
STIX ID: report--36b43b69-1e87-51a7-9a39-0a1daac289c1
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets major Chromium-based and Gecko-based browsers on Windows to extract passwords, cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history. It bypasses App-Bound Encryption in modern Chromium builds by spawning a headless browser and injecting a DLL via Early Bird APC to call the IElevator COM interface, uses DPAPI or NSS decryption where applicable, and includes multiple operational evasion techniques; the tool is intended for red team use but represents a high-risk capability for credential theft and cloud account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
