Hacking Tools, Hacker News & Cyber Security
ID: fcebabfd-6432-5ae0-ae20-57f25e89d715
STIX ID: report--fcebabfd-6432-5ae0-ae20-57f25e89d715
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts browser-stored secrets (passwords, cookies, OAuth refresh tokens, credit cards, autofill data, history, bookmarks) from Chromium-based browsers and Firefox. It bypasses Chrome's App-Bound Encryption (Chrome 127+) by spawning a headless Chromium process and injecting a DLL (Early Bird APC) to use the IElevator COM interface to decrypt the app_bound_encrypted_key, handles DPAPI-based browsers and NSS-based Firefox logins, includes multiple evasion techniques, and is intended for red-team assumed-breach testing but represents a high-risk capability if used maliciously.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
