Hacking Tools, Hacker News & Cyber Security
ID: 47c61d48-5c37-59ed-83eb-9673cffe0442
STIX ID: report--47c61d48-5c37-59ed-83eb-9673cffe0442
Feed Name: Darknet
DumpBrowserSecrets is a publicly released post‑exploitation tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from major browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox). It implements an App‑Bound Encryption bypass for Chromium-based browsers by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt the app_bound_encrypted_key, and includes multiple operational evasion features to reduce EDR detection; output is written as structured JSON for red team or operator use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
