logo

Hacking Tools, Hacker News & Cyber Security

ID: 43061987-c291-5f8d-a901-e881b7f9dfca

STIX ID: report--43061987-c291-5f8d-a901-e881b7f9dfca

Feed Name: Darknet

Threat Score
72/100

Date Published: 2010-01-11

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major Windows browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox). It bypasses Chromium App-Bound Encryption by spawning a headless Chromium process and injecting a DLL (Early Bird APC) to use the IElevator COM interface to decrypt app-bound keys, uses DPAPI/NSS handling for other browsers, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, and a custom SQLite parser); output is structured JSON suitable for red team or malicious reuse, and the report highlights detection opportunities and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.