Hacking Tools, Hacker News & Cyber Security
ID: 6ae75888-33ff-5bec-afb0-d45ad55bc7fd
STIX ID: report--6ae75888-33ff-5bec-afb0-d45ad55bc7fd
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation credential-harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card numbers and browsing data from Chromium-based and Gecko-based browsers. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL (Early Bird APC) to use the IElevator COM interface, retrieves DPAPI-protected keys for some browsers and uses NSS decryption for Firefox; the tool includes evasion features, writes structured JSON output, and can enable rapid lateral movement and cloud account takeover if abused.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
