logo

Hacking Tools, Hacker News & Cyber Security

ID: 0e1245a1-2ea3-567a-b946-991cfff28dff

STIX ID: report--0e1245a1-2ea3-567a-b946-991cfff28dff

Feed Name: Darknet

Threat Score
75/100

Date Published: 2014-03-31

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that targets Chrome, Edge, Brave (App‑Bound Encryption), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS) to extract saved passwords, cookies, OAuth tokens, credit cards, autofill data and history. It uses a compiled executable plus a DLL injected into a headless Chromium process (Early Bird APC injection) to leverage the IElevator COM interface and decrypt app_bound_encrypted_key, implements evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is presented as a red‑team tool useful for testing endpoint controls and realistic credential blast radius.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.