logo

Hacking Tools, Hacker News & Cyber Security

ID: 50ffb8f9-9862-52cb-b873-52dafb65602b

STIX ID: report--50ffb8f9-9862-52cb-b873-52dafb65602b

Feed Name: Darknet

Threat Score
75/100

Date Published: 2016-09-23

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly documented post‑exploitation credential‑harvesting tool that targets major Chromium and Gecko browsers on Windows to extract saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history. It implements an App‑Bound Encryption bypass for Chrome/Brave/Edge by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface (and uses DPAPI/NSS methods for other browsers), includes multiple operational evasion techniques, outputs structured JSON for red‑team use, and is relevant for testing detection and mitigation of browser‑based credential theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.