Hacking Tools, Hacker News & Cyber Security
ID: 85e7a6d3-4b09-5d31-9120-52ec61d7543e
STIX ID: report--85e7a6d3-4b09-5d31-9120-52ec61d7543e
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox on Windows; it bypasses Chrome's App-Bound Encryption by injecting a DLL into a headless Chromium process to use the IElevator COM interface, leverages DPAPI/NSS decryption where applicable, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), and the report describes usage, detection opportunities, and mitigation advice for red team and defensive testing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
