logo

Hacking Tools, Hacker News & Cyber Security

ID: 28852aaa-f9f2-5a82-8643-8ece7a220f4c

STIX ID: report--28852aaa-f9f2-5a82-8643-8ece7a220f4c

Feed Name: Darknet

Threat Score
75/100

Date Published: 2017-01-27

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post-exploitation tool that extracts browser-stored secrets (saved credentials, session cookies, OAuth refresh tokens, credit cards, autofill and history) from Chromium-based browsers and Firefox. It implements a sophisticated App-Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface, and returns decrypted keys to locally parse and decrypt browser SQLite/JSON stores; Opera-family browsers use DPAPI extraction and Firefox uses NSS decryption. The tool includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON for red-team use, and poses a substantive risk for cloud account takeover and lateral movement if misused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.