logo

Hacking Tools, Hacker News & Cyber Security

ID: 3b131c5e-f114-586d-869c-76b39cdefb9b

STIX ID: report--3b131c5e-f114-586d-869c-76b39cdefb9b

Feed Name: Darknet

Threat Score
78/100

Date Published: 2018-11-28

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a public post-exploitation tool that harvests browser-stored credentials and session tokens from major Windows browsers (Chrome/Edge/Brave via App-Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It spawns a headless Chromium process and injects a DLL using Early Bird APC to leverage the IElevator COM interface to decrypt app_bound_encrypted_key, then parses browser SQLite/JSON stores to output structured JSON containing cookies, OAuth refresh tokens, saved logins, autofill data and history, and includes operational evasion features aimed at defeating EDRs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.