logo

Hacking Tools, Hacker News & Cyber Security

ID: 0cb48039-3548-51b8-80d0-ec3e02115934

STIX ID: report--0cb48039-3548-51b8-80d0-ec3e02115934

Feed Name: Darknet

Threat Score
75/100

Date Published: 2015-08-05

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post-exploitation credential-extraction tool that targets Chromium-based and Firefox browsers to recover saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and history. It implements an App-Bound Encryption bypass for Chrome 127+ by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface, retrieves DPAPI keys for some Chromium forks, and uses NSS decryption for Firefox; the tool includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection, custom SQLite parsing) and is distributed as a precompiled executable intended for red team use but easily repurposed by attackers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.