Hacking Tools, Hacker News & Cyber Security
ID: aba2a6ae-36b0-5a95-8632-ce266d6a7013
STIX ID: report--aba2a6ae-36b0-5a95-8632-ce266d6a7013
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major Windows browsers. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL (Early Bird APC + IElevator COM) to decrypt encryption keys, handles DPAPI and NSS models for other browsers, includes operational evasion features, and produces structured JSON output — making it relevant for red teams and potentially for real-world misuse that could enable cloud account takeover and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
