logo

Hacking Tools, Hacker News & Cyber Security

ID: 0f6e4bc4-f565-577b-9b83-c5d26c944f07

STIX ID: report--0f6e4bc4-f565-577b-9b83-c5d26c944f07

Feed Name: Darknet

Threat Score
75/100

Date Published: 2017-01-02

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that targets major Windows browsers (Chrome, Edge, Brave, Opera family, Vivaldi, Firefox) to extract saved credentials, session cookies, OAuth refresh tokens and other sensitive browser data. The tool bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface, retrieves DPAPI/NSS keys for other browsers, and writes structured JSON output; it includes multiple evasion features to reduce EDR detection and is presented as a red team tool but could be abused by adversaries. Detection focuses on anomalous process injection into browser processes, headless browser instantiation, non‑browser reads of browser SQLite databases, and IElevator COM calls; mitigation includes using dedicated credential managers and EDR rules that monitor these behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.