logo

Hacking Tools, Hacker News & Cyber Security

ID: 302e82e1-4008-50bd-9267-7072d13e54f4

STIX ID: report--302e82e1-4008-50bd-9267-7072d13e54f4

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-05-31

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts browser‑stored secrets (cookies, saved logins, OAuth refresh tokens, credit cards, autofill, history, bookmarks) from Chromium‑based browsers (Chrome, Edge, Brave using App‑Bound Encryption), Opera/Vivaldi (DPAPI), and Firefox (NSS). The tool uses a two‑component design (an executable and an injected DLL) to spawn a headless Chromium process and perform Early Bird APC DLL injection to call the IElevator COM interface and decrypt app_bound_encrypted_key, with additional evasion measures (string obfuscation, API hashing, PPID/argument spoofing, handle duplication) and outputs structured JSON for red team use and testing detection controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.