Hacking Tools, Hacker News & Cyber Security
ID: e2f33995-9dce-588d-a1e2-d1647f0d30dc
STIX ID: report--e2f33995-9dce-588d-a1e2-d1647f0d30dc
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts saved logins, cookies, OAuth refresh tokens, credit card data, autofill entries, history and bookmarks from Chromium‑based and Firefox browsers. It bypasses Chrome’s App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL that uses the IElevator COM interface to decrypt the app_bound_encrypted_key, uses DPAPI or NSS methods for other browsers, and includes multiple evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parsing) to evade EDRs; output is structured JSON intended for red teams but applicable to malicious actors for cloud account takeover and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
