Hacker Posts List of Compromised User Accounts Online
ID: 666fdb95-6a37-56cb-8698-b3e7b1241c7d
STIX ID: report--666fdb95-6a37-56cb-8698-b3e7b1241c7d
Feed Name: Darknet
DumpBrowserSecrets is a publicly released post‑exploitation tool that harvests credentials and session tokens from major Windows browsers (Chrome/Edge/Brave with App‑Bound Encryption, Opera/Vivaldi with DPAPI, and Firefox with NSS). It uses headless Chromium process spawning and Early Bird APC DLL injection to invoke the IElevator COM interface and decrypt app_bound_encrypted_key, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), and outputs structured JSON of extracted secrets for lateral movement and cloud account takeover testing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
