logo

Hacking Tools, Hacker News & Cyber Security

ID: 7484dd43-a69b-5e9f-8cc4-43e233e6ad56

STIX ID: report--7484dd43-a69b-5e9f-8cc4-43e233e6ad56

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-11-03

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a public post-exploitation tool and red-team utility that extracts browser-stored secrets (saved logins, session cookies, OAuth tokens, credit card data, autofill, history, bookmarks) from Chromium-based and Firefox browsers on Windows. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface, uses DPAPI extraction for some browsers and NSS handling for Firefox, and includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication). The report details usage, extracted data types, an attacker scenario, detection points (unusual process injection, headless browser use, IElevator calls, reads of browser SQLite files), and mitigation recommendations (use external credential managers and EDRs that monitor IElevator/headless browser behavior).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.