Hacking Tools, Hacker News & Cyber Security
ID: ed890b69-3464-501b-84f1-1af7f55acfd6
STIX ID: report--ed890b69-3464-501b-84f1-1af7f55acfd6
Feed Name: Darknet
### Executive summary: DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, Firefox). It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface, handles DPAPI and NSS decryption for other browsers, includes multiple EDR-evasion features, outputs structured JSON, and is intended for red-team assumed-breach assessments but represents a high-risk infostealer capability for compromised developer endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
