logo

Hacking Tools, Hacker News & Cyber Security

ID: 472deb58-a38d-584e-850b-43fcb213cfbe

STIX ID: report--472deb58-a38d-584e-850b-43fcb213cfbe

Feed Name: Darknet

Threat Score
75/100

Date Published: 2011-07-18

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post-exploitation credential-harvesting tool (available as a compiled executable and optional DLL) that extracts cookies, saved logins, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks from major browsers. It implements an App-Bound Encryption bypass for Chromium-based browsers by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface, retrieves DPAPI keys for Opera-family browsers, and uses NSS decryption for Firefox; the tool includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication) and writes structured JSON output for red team use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.