logo

Hacking Tools, Hacker News & Cyber Security

ID: 5dd7279f-48b9-563b-a0a2-54d0487d55a0

STIX ID: report--5dd7279f-48b9-563b-a0a2-54d0487d55a0

Feed Name: Darknet

Threat Score
70/100

Date Published: 2016-05-03

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly documented post‑exploitation tool that extracts browser‑stored credentials and session tokens from major Chromium- and Gecko-based browsers on Windows; it implements an App‑Bound Encryption bypass for Chrome/Edge/Brave via spawning a headless Chromium instance and DLL injection (Early Bird APC) to use the IElevator COM interface, handles DPAPI for Opera/Vivaldi, and uses NSS decryption for Firefox. The report covers extracted data types, operational evasion features, usage examples, detection opportunities (process injection, headless browser instantiation, IElevator calls, reads of browser SQLite DBs), and mitigation recommendations such as moving secrets to native password managers and EDR detection of IElevator/headless behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.