Hacking Tools, Hacker News & Cyber Security
ID: 46826eef-ab2f-57d2-945b-0b4abde1e25e
STIX ID: report--46826eef-ab2f-57d2-945b-0b4abde1e25e
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from Chromium-based browsers (Chrome, Edge, Brave, Opera, Vivaldi) and Firefox by bypassing App-Bound Encryption (via an IElevator COM-based technique injected into a headless Chromium process) and DPAPI/NSS protections; it uses Early Bird APC DLL injection, handle duplication, API hashing and PPID/argument spoofing for evasion, outputs structured JSON, and is positioned for red-team/assumed-breach testing but has clear malicious utility.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
