logo

Hacking Tools, Hacker News & Cyber Security

ID: 5c266763-d374-542e-8db7-0dcb3918f59e

STIX ID: report--5c266763-d374-542e-8db7-0dcb3918f59e

Feed Name: Darknet

Threat Score
75/100

Date Published: 2017-09-26

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation browser credential‑harvesting tool that extracts saved logins, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from Chromium‑based and Gecko‑based browsers. It implements an App‑Bound Encryption bypass for Chrome/Brave/Edge by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface and retrieve decryption keys, and uses DPAPI/NSS handling for other browsers; the tool includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser) and outputs structured JSON suitable for red‑team and post‑exploitation use, posing a significant risk to cloud and SaaS account takeover on compromised developer endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.