Hacking Tools, Hacker News & Cyber Security
ID: a94a01ac-2d08-52d4-a0cf-8fd64e5c5403
STIX ID: report--a94a01ac-2d08-52d4-a0cf-8fd64e5c5403
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials and tokens from major browsers (Chrome/Edge/Brave via App-Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It uses headless Chromium + Early Bird APC DLL injection to call the IElevator COM interface and decrypt app_bound_encrypted_key, extracts SQLite/JSON-stored secrets to structured JSON, includes evasion features to resist EDR, and poses a rapid, high-impact risk for cloud account/session takeover from compromised developer endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
