Hacking Tools, Hacker News & Cyber Security
ID: d344e19d-cb0d-5a2b-a1ac-eda43bdaab04
STIX ID: report--d344e19d-cb0d-5a2b-a1ac-eda43bdaab04
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation credential-harvester targeted at Windows developer endpoints and enterprise workstations. It supports Chromium-based (Chrome, Edge, Brave) and Gecko-based (Firefox) browsers and uses a headless Chromium process plus Early Bird APC DLL injection and the IElevator COM interface to bypass App-Bound Encryption, plus DPAPI/NSS handling for other browsers. The tool extracts cookies, saved logins, OAuth refresh tokens, credit cards, autofill data and history into structured JSON, includes multiple EDR-evasion primitives (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), and is presented as a red-team tool for assessing credential exposure and detection efficacy.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
