Hacking Tools, Hacker News & Cyber Security
ID: 8f858b28-2894-52db-aadf-78c2d9c496ac
STIX ID: report--8f858b28-2894-52db-aadf-78c2d9c496ac
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored credentials and session tokens from Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox by bypassing App-Bound Encryption via injected DLLs into a headless Chromium process (using Early Bird APC and the IElevator COM interface) and by extracting DPAPI/NSS keys where applicable; it outputs structured JSON, includes operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication, custom SQLite parsing), and presents a significant risk for lateral movement and cloud account takeover while also offering detection and mitigation guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
