logo

Hacking Tools, Hacker News & Cyber Security

ID: 4c309943-0ce1-5b86-a742-a935a8775ec0

STIX ID: report--4c309943-0ce1-5b86-a742-a935a8775ec0

Feed Name: Darknet

Threat Score
75/100

Date Published: 2011-07-26

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a publicly-available post-exploitation tool that harvests browser-stored credentials and tokens from major browsers (Chrome/Edge/Brave via App-Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It uses headless Chromium DLL injection (Early Bird APC) and the IElevator COM interface to decrypt app-bound keys, supports handle duplication to read locked SQLite files, and outputs structured JSON of extracted cookies, saved logins, OAuth refresh tokens, credit cards, autofill data and history—making it a high-value primitive for lateral movement and cloud account takeover in assumed-breach exercises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.