logo

Hacking Tools, Hacker News & Cyber Security

ID: 652f396e-df3b-5e6f-a728-0b8acc1473fb

STIX ID: report--652f396e-df3b-5e6f-a728-0b8acc1473fb

Feed Name: Darknet

Threat Score
75/100

Date Published: 2008-07-24

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post‑exploitation credential‑harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, and other browser-stored secrets from Chromium-based (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox browsers. It includes an App‑Bound Encryption bypass for modern Chromium builds by spawning a headless browser and using in‑process DLL injection with the IElevator COM interface, handles DPAPI and NSS decryption models, and implements operational evasion (string obfuscation, API hashing, PPID/argument spoofing, handle duplication). The report outlines usage, attack scenarios demonstrating rapid credential collection enabling cloud account takeover and lateral movement, and detection/mitigation guidance such as monitoring IElevator calls, headless browser instantiation, and moving secrets to native password managers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.