logo

Hacking Tools, Hacker News & Cyber Security

ID: 2a35e95a-78df-5bf3-bbf9-cfa7c26a6a16

STIX ID: report--2a35e95a-78df-5bf3-bbf9-cfa7c26a6a16

Feed Name: Darknet

Threat Score
75/100

Date Published: 2016-03-28

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a public post-exploitation tool that harvests credentials and session data from major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, Firefox) by using DLL injection into a headless Chromium process to bypass App-Bound Encryption (via the IElevator COM interface) and by extracting DPAPI or NSS-protected secrets where applicable; it outputs structured JSON and includes multiple evasion techniques aimed at reducing EDR detection. The report details capabilities, usage, attack scenarios (developer workstation compromise leading to SaaS/cloud account takeover), detection opportunities (process injection, IElevator calls, reads of browser SQLite files), and mitigation recommendations such as using dedicated credential managers and EDR rules that monitor IElevator and headless browser instantiation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.