logo

Hacking Tools, Hacker News & Cyber Security

ID: 3d17d781-0f92-5fa9-bcfb-da974ab87897

STIX ID: report--3d17d781-0f92-5fa9-bcfb-da974ab87897

Feed Name: Darknet

Threat Score
75/100

Date Published: 2016-02-02

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post-exploitation credential-harvesting tool that targets major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox) to extract saved passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, history, and bookmarks. The tool bypasses Chrome's App-Bound Encryption (Chrome 127+) by spawning a headless Chromium process and injecting a DLL that uses the IElevator COM interface to decrypt the app_bound_encrypted_key, and uses DPAPI or NSS handling for other browsers; it includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication) and outputs structured JSON for red-team use while highlighting detection and mitigation strategies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.