Hacking Tools, Hacker News & Cyber Security
ID: fc458ded-ce85-56da-aa0e-e1396fbe465d
STIX ID: report--fc458ded-ce85-56da-aa0e-e1396fbe465d
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential-harvesting tool designed to extract saved credentials, session cookies, OAuth refresh tokens, credit card data and browsing history from major Windows browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It implements an App‑Bound Encryption bypass for Chromium-based browsers by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface to decrypt keys, handles DPAPI and NSS models for other browsers, and includes multiple evasion features; the report covers usage, detection opportunities, and mitigation recommendations for enterprise defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
