logo

Hacking Tools, Hacker News & Cyber Security

ID: 0f2c27be-6ca4-51d5-a29b-0414353de990

STIX ID: report--0f2c27be-6ca4-51d5-a29b-0414353de990

Feed Name: Darknet

Threat Score
78/100

Date Published: 2015-09-16

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post-exploitation credential-harvesting tool that extracts saved passwords, cookies, OAuth tokens, credit cards and browsing history from Chromium-based and Firefox browsers. It bypasses Chrome App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL (Early Bird APC) to call the IElevator COM interface to decrypt keys, uses DPAPI/NSS handling for other browsers, and includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, custom SQLite parser). The report covers usage, attack scenarios, detection opportunities, and mitigations and frames the tool as a red-team utility that also demonstrates a significant real-world credential exposure risk when browser-stored secrets are trusted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.