Hacking Tools, Hacker News & Cyber Security
ID: 53e7becf-10cb-5e56-8a28-ca882c271805
STIX ID: report--53e7becf-10cb-5e56-8a28-ca882c271805
Feed Name: Darknet
DumpBrowserSecrets is a public post‑exploitation tool that harvests browser-stored credentials and tokens across Chromium-based browsers (including Chrome, Edge, Brave) and Firefox by bypassing App‑Bound Encryption and using DPAPI/NSS decryption; it employs Early Bird APC DLL injection into a headless browser process, leverages the IElevator COM interface to decrypt app_bound_encrypted_key, and includes multiple operational evasion techniques. The report documents supported browsers and data types, usage examples, attacker scenarios (fast lateral movement and SaaS account takeover), and detection/mitigation advice for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
