logo

Hacking Tools, Hacker News & Cyber Security

ID: 36b43b69-1e87-51a7-9a39-0a1daac289c1

STIX ID: report--36b43b69-1e87-51a7-9a39-0a1daac289c1

Feed Name: Darknet

Threat Score
75/100

Date Published: 2009-03-10

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets major Chromium-based and Gecko-based browsers on Windows to extract passwords, cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history. It bypasses App-Bound Encryption in modern Chromium builds by spawning a headless browser and injecting a DLL via Early Bird APC to call the IElevator COM interface, uses DPAPI or NSS decryption where applicable, and includes multiple operational evasion techniques; the tool is intended for red team use but represents a high-risk capability for credential theft and cloud account takeover.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.