logo

Hacking Tools, Hacker News & Cyber Security

ID: 2ac4c77a-2d1e-5a47-9103-58c5641ea585

STIX ID: report--2ac4c77a-2d1e-5a47-9103-58c5641ea585

Feed Name: Darknet

Threat Score
78/100

Date Published: 2006-03-05

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool for Windows that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox. It bypasses Chromium App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface (Early Bird APC injection), handles DPAPI for some Chromium forks and NSS for Firefox, includes operational evasion (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), and outputs structured JSON; the report covers usage, detection opportunities, and mitigations for red team and defensive validation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.