Hacking Tools, Hacker News & Cyber Security
ID: 8ebbf2b7-933e-5ea8-b698-6684b226d69c
STIX ID: report--8ebbf2b7-933e-5ea8-b698-6684b226d69c
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from Chromium-based (Chrome, Edge, Brave, Opera, Vivaldi) and Firefox browsers. The report explains the tool's architecture—an executable plus a DLL that uses Early Bird APC injection to run inside a headless Chromium process and call the IElevator COM interface to decrypt App-Bound Encryption keys—handling DPAPI and NSS models where applicable. It describes operational evasion features, usage examples, an assumed-breach attack scenario demonstrating rapid credential extraction and session replay potential, and detection/mitigation recommendations for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
