Hacking Tools, Hacker News & Cyber Security
ID: f53598a5-3e8d-5fc6-b0c3-e048d9b9646e
STIX ID: report--f53598a5-3e8d-5fc6-b0c3-e048d9b9646e
Feed Name: Darknet
DumpBrowserSecrets is a Windows post‑exploitation tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from major Chromium-based browsers and Firefox by bypassing App‑Bound Encryption (Chrome 127+) and other local encryption models; it uses headless Chromium, Early Bird APC DLL injection and the IElevator COM interface to decrypt keys in-process, outputs structured JSON, and includes evasion features aimed at reducing EDR detection—making it highly relevant for red teams and a potent capability if abused by threat actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
