logo

Hacking Tools, Hacker News & Cyber Security

ID: 25753ba0-3fc8-51a4-a128-6f642a61ce83

STIX ID: report--25753ba0-3fc8-51a4-a128-6f642a61ce83

Feed Name: Darknet

Threat Score
78/100

Date Published: 2009-07-17

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts saved logins, session cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks from Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox. The tool implements an App‑Bound Encryption bypass for Chromium browsers by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface to decrypt the app_bound_encrypted_key; it also supports DPAPI and NSS decryption paths, includes multiple runtime evasion techniques, and outputs structured JSON for red‑team use, enabling rapid lateral movement and cloud account takeovers if deployed on a compromised host.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.