Hacking Tools, Hacker News & Cyber Security
ID: c3d8ccc8-bf59-58bb-8dc1-64f2ef4189de
STIX ID: report--c3d8ccc8-bf59-58bb-8dc1-64f2ef4189de
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests saved credentials, session cookies, OAuth refresh tokens, credit card data and browsing history from major Chromium-based browsers and Firefox by using DLL injection and an IElevator COM interface bypass to decrypt App-Bound Encryption keys (Chrome/Edge/Brave), DPAPI key retrieval for Opera-derived browsers, and NSS decryption for Firefox; the report covers technical implementation, supported browsers, extracted data types, evasion techniques (Early Bird APC injection, PPID/argument spoofing, API hashing), usage examples, detection opportunities, and mitigation recommendations, and frames the tool as a red-team utility with significant implications for cloud account takeover and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
