Hacking Tools, Hacker News & Cyber Security
ID: f3595a9c-7285-5ab0-893f-5eae4852df5c
STIX ID: report--f3595a9c-7285-5ab0-893f-5eae4852df5c
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that extracts saved credentials, session cookies, OAuth tokens, credit-card and autofill data from major browsers (Chrome/Edge/Brave via App-Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It accomplishes this by spawning headless browser processes and injecting a DLL to use the IElevator COM interface to decrypt keys, includes multiple operational evasion features, outputs structured JSON for operators, and is relevant both to red teams and malicious actors seeking rapid account takeover and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
