logo

Hacking Tools, Hacker News & Cyber Security

ID: 640abdae-14c0-5600-9df2-4bedce5b2569

STIX ID: report--640abdae-14c0-5600-9df2-4bedce5b2569

Feed Name: Darknet

Threat Score
75/100

Date Published: 2016-03-14

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post‑exploitation credential‑harvesting tool (with accompanying DLL) that targets Chromium‑based and Gecko‑based browsers to extract saved passwords, session cookies, OAuth refresh tokens, credit card numbers, autofill data and history. It bypasses Chrome's App‑Bound Encryption (Chrome 127+) by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt keys, handles DPAPI and NSS decryption for other browsers, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), writes structured JSON output, and is emphasized as a red‑team tool for assessing credential exposure and endpoint detection controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.