logo

Hacking Tools, Hacker News & Cyber Security

ID: 32234887-db6a-5dca-8699-d93071e73f33

STIX ID: report--32234887-db6a-5dca-8699-d93071e73f33

Feed Name: Darknet

Threat Score
75/100

Date Published: 2008-04-21

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser-stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill, history) from Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It uses a headless Chromium spawn with Early Bird APC DLL injection to leverage the IElevator COM interface and bypass App‑Bound Encryption, handles DPAPI and NSS decryption for other browsers, and includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication). The report covers usage, attack scenarios, detection signals, and mitigation recommendations, noting the tool is intended for red team use but is functionally capable of enabling credential theft and cloud account takeover if abused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.