logo

Hacking Tools, Hacker News & Cyber Security

ID: 0e2dac88-66d6-5f81-9388-1f0659a19e47

STIX ID: report--0e2dac88-66d6-5f81-9388-1f0659a19e47

Feed Name: Darknet

Threat Score
75/100

Date Published: 2009-11-03

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox) to extract saved passwords, session cookies, OAuth refresh tokens, credit card numbers, autofill data, and browsing history. It bypasses Chrome's App-Bound Encryption (Chrome 127+) by injecting a DLL into a headless Chromium process and using the IElevator COM interface to decrypt encryption keys, and it includes operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, file handle duplication, and a custom SQLite parser). The report includes usage details, an attack scenario demonstrating rapid credential extraction for lateral movement or cloud account takeover, and recommended detection and mitigation strategies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.