logo

Hacking Tools, Hacker News & Cyber Security

ID: 4b72915c-79b5-582c-8379-d66ae040ba6e

STIX ID: report--4b72915c-79b5-582c-8379-d66ae040ba6e

Feed Name: Darknet

Threat Score
75/100

Date Published: 2009-03-03

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available Windows post-exploitation tool that harvests browser-stored credentials and session artifacts (passwords, cookies, OAuth tokens, credit cards, autofill, history) from Chrome/Edge/Brave (App-Bound Encryption bypass), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS). It uses DLL injection into a headless Chromium process to decrypt app_bound_encrypted_key via the IElevator COM interface, includes operational evasion techniques to evade EDR, outputs structured JSON for red team use, and poses a high-risk capability enabling cloud account takeover and lateral movement if used by malicious actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.