Hacking Tools, Hacker News & Cyber Security
ID: 907448ed-0653-5209-a72b-3e3ad0c34d60
STIX ID: report--907448ed-0653-5209-a72b-3e3ad0c34d60
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, history and bookmarks from major browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox). It implements an App‑Bound Encryption bypass for Chromium-based browsers by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt the app_bound_encrypted_key, uses DPAPI or NSS where applicable, outputs structured JSON, and includes multiple evasion features intended to reduce EDR detection in red team or offensive scenarios.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
