logo

Hacking Tools, Hacker News & Cyber Security

ID: 07d0b281-7565-585d-aa01-3ebbcfd33cbc

STIX ID: report--07d0b281-7565-585d-aa01-3ebbcfd33cbc

Feed Name: Darknet

Threat Score
70/100

Date Published: 2017-02-13

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser‑stored credentials and session tokens from major Chromium‑based browsers and Firefox. It implements an App‑Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt the app_bound_encrypted_key, retrieves DPAPI keys for some browsers, and handles Firefox NSS decryption directly. The tool outputs structured JSON, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parsing), and is positioned for red team/useful to attackers because recovered cookies and OAuth refresh tokens enable cloud account takeover and lateral movement; the report also outlines detection and mitigation opportunities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.