logo

Hacking Tools, Hacker News & Cyber Security

ID: 5126f9cd-7efd-5e14-b132-7a03a7f4c1bb

STIX ID: report--5126f9cd-7efd-5e14-b132-7a03a7f4c1bb

Feed Name: Darknet

Threat Score
78/100

Date Published: 2010-08-23

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a publicly available post-exploitation credential-harvesting tool for Windows that extracts saved credentials, session cookies, OAuth tokens, credit card details, autofill data, and history from major Chromium-based and Firefox browsers. It implements an App-Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface, retrieves DPAPI keys for Opera/Vivaldi, and uses NSS decryption for Firefox; the tool includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-lock bypass) and outputs structured JSON suitable for session replay and lateral movement, with guidance on detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.