logo

Hacking Tools, Hacker News & Cyber Security

ID: 5073a027-afc8-54df-bb2d-26e1d7cc80cc

STIX ID: report--5073a027-afc8-54df-bb2d-26e1d7cc80cc

Feed Name: Darknet

Threat Score
80/100

Date Published: 2011-11-21

Date Updated: 2026-05-18

...
...

DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored secrets (saved credentials, session cookies, OAuth refresh tokens, credit cards, autofill, and history) across major Chromium-based and Firefox browsers. It implements an App-Bound Encryption bypass for Chrome/Brave/Edge by spawning a headless Chromium process and injecting a DLL (Early Bird APC) to call the IElevator COM interface, handles DPAPI-based browsers and NSS-based Firefox logins, includes operational evasion (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and outputs structured JSON for rapid credential theft and session replay; the report also provides detection and mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.