Hacking Tools, Hacker News & Cyber Security
ID: 4492cdb8-588f-5457-8466-d843ec211f67
STIX ID: report--4492cdb8-588f-5457-8466-d843ec211f67
Feed Name: Darknet
DumpBrowserSecrets is a Windows post‑exploitation credential‑harvesting tool that targets major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, Firefox) to extract saved passwords, cookies, OAuth refresh tokens, credit cards, autofill data and browsing history. It uses a two‑component design (an executable and a DLL) and performs Early Bird APC DLL injection into a headless Chromium process to leverage the IElevator COM interface and decrypt App‑Bound Encryption keys (Chrome 127+), with alternative methods for DPAPI and Firefox NSS; the report covers usage, evasion features, detection opportunities and mitigations and emphasizes its red‑team relevance and operational risk to developer workstations and enterprise SaaS sessions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
