logo

Hacking Tools, Hacker News & Cyber Security

ID: 2e382890-9bca-50d0-87d9-3b32e79ecb83

STIX ID: report--2e382890-9bca-50d0-87d9-3b32e79ecb83

Feed Name: Darknet

Threat Score
75/100

Date Published: 2009-04-02

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a publicly documented post-exploitation tool designed to harvest credentials and session tokens from major Windows browsers (Chrome, Edge, Brave, Opera family, Vivaldi, and Firefox). It implements an App-Bound Encryption bypass for Chromium-based browsers by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt the app_bound_encrypted_key, and then parses and decrypts on-disk browser data (or uses DPAPI/NSS where applicable). The tool outputs structured JSON, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and is positioned for red-team/assumed-breach use to demonstrate credential exposure and test endpoint defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.