Hacking Tools, Hacker News & Cyber Security
ID: c3f250f9-c505-510d-9a97-44302c69a4d3
STIX ID: report--c3f250f9-c505-510d-9a97-44302c69a4d3
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation credential-extraction tool that targets Chromium-based browsers (including Chrome/Edge/Brave with App-Bound Encryption) and Firefox to retrieve saved passwords, session cookies, OAuth tokens, credit cards, autofill data, and history. It performs an IElevator COM-based App-Bound Encryption bypass by injecting a DLL into a headless Chromium process (Early Bird APC injection), supports DPAPI and NSS decryption, includes multiple evasion techniques, and is intended for red-team testing but poses significant risk if misused for lateral movement or SaaS account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
