logo

Hacking Tools, Hacker News & Cyber Security

ID: 396e5cf4-1b13-5893-9c06-5c00810adf1b

STIX ID: report--396e5cf4-1b13-5893-9c06-5c00810adf1b

Feed Name: Darknet

Threat Score
75/100

Date Published: 2007-01-02

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that targets Chrome, Edge, Brave (via App‑Bound Encryption bypass), Opera/ Vivaldi/Opera GX (DPAPI), and Firefox (NSS) to extract saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and history. It uses Early Bird APC DLL injection into a headless Chromium process to call the IElevator COM interface and decrypt app_bound_encrypted_key, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), writes structured JSON output, and is positioned for red team/assumed‑breach testing but presents clear risk if abused by adversaries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.