Hacking Tools, Hacker News & Cyber Security
ID: 66aa189d-03d0-5552-a631-885c3e205d73
STIX ID: report--66aa189d-03d0-5552-a631-885c3e205d73
Feed Name: Darknet
DumpBrowserSecrets is a Windows post‑exploitation tool that harvests browser‑stored credentials and session tokens from major Chromium and Gecko browsers by using techniques including Early Bird APC DLL injection, IElevator COM interface to bypass Chrome App‑Bound Encryption, DPAPI/NSS decryption, and file‑handle duplication to read locked SQLite databases. It outputs structured JSON, includes multiple EDR‑evasion features, and is intended for red‑team assumed‑breach testing but also poses a credible risk if adopted by adversaries because stolen cookies and OAuth tokens enable rapid cloud account takeover and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
