logo

Hacking Tools, Hacker News & Cyber Security

ID: 732e4168-96f0-5c56-8259-9a4a4a603160

STIX ID: report--732e4168-96f0-5c56-8259-9a4a4a603160

Feed Name: Darknet

Threat Score
75/100

Date Published: 2007-01-14

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets major Windows browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox) to extract passwords, cookies, OAuth tokens, credit card data, autofill entries, and history. It implements an App‑Bound Encryption bypass for Chromium-based browsers by spawning a headless browser and injecting a DLL via Early Bird APC to use the IElevator COM interface, handles DPAPI and NSS-based storage for other browsers, and includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication). The tool is presented as a red-team utility but poses a realistic threat to enterprises because recovered tokens and cookies can enable cloud account takeover and lateral movement; recommended detection and mitigation focus on monitoring IElevator calls, anomalous headless browser instantiation, and moving secrets out of browser storage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.