Hacking Tools, Hacker News & Cyber Security
ID: ba1f576b-5a7e-5d23-86b7-e19a4f7beb26
STIX ID: report--ba1f576b-5a7e-5d23-86b7-e19a4f7beb26
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool (executable + DLL) that harvests browser-stored secrets across Chrome/Brave/Edge (App-Bound Encryption bypass), Opera/Vivaldi (DPAPI), and Firefox (NSS). It uses Early Bird APC DLL injection into a spawned headless Chromium process to call the IElevator COM interface and decrypt app-bound keys, extracts cookies, logins, OAuth tokens, credit cards and history to JSON, includes multiple evasion features to reduce EDR detection, and is intended for red-team/assumed-breach testing but poses significant real-world abuse risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
