Hacking Tools, Hacker News & Cyber Security
ID: 3ac10149-0850-5eff-b087-30dbffe1d4b6
STIX ID: report--3ac10149-0850-5eff-b087-30dbffe1d4b6
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation browser credential harvester that extracts saved passwords, session cookies, OAuth refresh tokens, credit card details, autofill data and browsing history from Chrome, Edge, Brave, Opera (and forks), Vivaldi and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL (Early Bird APC + IElevator COM) to decrypt the app_bound_encrypted_key, includes DPAPI and NSS handling for other browsers, and implements operational evasion techniques; output is written as structured JSON for red-team or adversary use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
