logo

Hacking Tools, Hacker News & Cyber Security

ID: 0f5108a1-9026-5d35-8cd7-a170a49a251a

STIX ID: report--0f5108a1-9026-5d35-8cd7-a170a49a251a

Feed Name: Darknet

Threat Score
75/100

Date Published: 2017-07-03

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool that harvests credentials and session tokens from major Windows browsers — handling Chrome/Brave/Edge via an App‑Bound Encryption (IElevator) bypass, Opera/Opera GX/Vivaldi via DPAPI, and Firefox via NSS — by spawning a headless Chromium process and injecting a DLL to decrypt keys, then parsing and decrypting on-disk browser stores. The tool includes operational evasion features, outputs structured JSON for red-team use, and poses a significant risk for cloud account takeover and lateral movement if used by adversaries against developer or enterprise endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.