logo

Hacking Tools, Hacker News & Cyber Security

ID: 66aa189d-03d0-5552-a631-885c3e205d73

STIX ID: report--66aa189d-03d0-5552-a631-885c3e205d73

Feed Name: Darknet

Threat Score
75/100

Date Published: 2018-07-21

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post‑exploitation tool that harvests browser‑stored credentials and session tokens from major Chromium and Gecko browsers by using techniques including Early Bird APC DLL injection, IElevator COM interface to bypass Chrome App‑Bound Encryption, DPAPI/NSS decryption, and file‑handle duplication to read locked SQLite databases. It outputs structured JSON, includes multiple EDR‑evasion features, and is intended for red‑team assumed‑breach testing but also poses a credible risk if adopted by adversaries because stolen cookies and OAuth tokens enable rapid cloud account takeover and lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.