Hacking Tools, Hacker News & Cyber Security
ID: 63a97074-9534-5340-82c7-c091df6d55e1
STIX ID: report--63a97074-9534-5340-82c7-c091df6d55e1
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential exfiltration tool that targets major browsers (Chrome, Edge, Brave, Opera family, Vivaldi, Firefox) to extract saved logins, session cookies, OAuth refresh tokens, credit cards, autofill data and history; it bypasses Chromium App-Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface, includes DPAPI/NSS handling for other browsers, and implements multiple evasion techniques—intended for red-team testing but representing a high-risk credential-theft capability for enterprise endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
