logo

Hacking Tools, Hacker News & Cyber Security

ID: 09a19d1c-a223-5e36-a6cc-83e6695ba741

STIX ID: report--09a19d1c-a223-5e36-a6cc-83e6695ba741

Feed Name: Darknet

Threat Score
75/100

Date Published: 2007-07-13

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a publicly available post‑exploitation tool designed to harvest browser-stored secrets from major Windows browsers (Chrome/Edge/Brave via an App‑Bound Encryption bypass using IElevator, Opera/Vivaldi via DPAPI, and Firefox via NSS decryption). It injects a DLL into a headless Chromium process using Early Bird APC to decrypt app-bound keys, extracts cookies, saved logins, OAuth refresh tokens and other sensitive data, includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and is intended for red team assumed‑breach testing but represents a high‑impact credential theft capability if used by real attackers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.