logo

Hacking Tools, Hacker News & Cyber Security

ID: 2e17d24c-6dad-53c0-876f-3e6bfcfbbf2b

STIX ID: report--2e17d24c-6dad-53c0-876f-3e6bfcfbbf2b

Feed Name: Darknet

Threat Score
75/100

Date Published: 2007-12-12

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post‑exploitation tool (published as a precompiled executable + DLL) designed to extract saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, history and bookmarks from Chromium-based and Firefox browsers. It bypasses Chrome's App‑Bound Encryption (Chrome 127+) by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface (Early Bird APC injection), retrieves DPAPI keys for some Chromium forks, and handles Firefox NSS decryption directly. The tool includes operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON, and is presented as a red-team/assumed-breach testing utility while being clearly usable for malicious credential theft; the report also includes detection and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.