logo

Hacking Tools, Hacker News & Cyber Security

ID: 45769250-13f2-535b-9dfd-515da2881e71

STIX ID: report--45769250-13f2-535b-9dfd-515da2881e71

Feed Name: Darknet

Threat Score
75/100

Date Published: 2016-08-02

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly released post‑exploitation tool that harvests browser‑stored secrets from Chrome, Edge, Brave (App‑Bound Encryption bypass), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS). It uses a compiled executable plus a DLL injected into a headless Chromium process to decrypt app_bound_encrypted_key via the IElevator COM interface, extracts SQLite/JSON data (logins, cookies, OAuth tokens, cards, history), and includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, file‑handle duplication). The report discusses use cases for red teams, detection opportunities (injection, IElevator calls, non‑browser reads of Login Data/Cookies/Web Data), and mitigation recommendations such as moving secrets out of browsers to dedicated credential managers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.