logo

Hacking Tools, Hacker News & Cyber Security

ID: 7c949f84-f56b-5e2c-9139-967d7ecf0d30

STIX ID: report--7c949f84-f56b-5e2c-9139-967d7ecf0d30

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-06-11

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a publicly available post‑exploitation tool (executable + DLL) that harvests browser-stored secrets from major Chromium-based and Firefox browsers on Windows. It implements an IElevator COM bypass by injecting a DLL into a headless Chromium process via Early Bird APC to decrypt App‑Bound Encryption keys (Chrome/Edge/Brave), uses DPAPI extraction for Opera-family browsers, and NSS decryption for Firefox; extracted data includes session cookies, OAuth refresh tokens, saved passwords, credit cards, autofill, and history. The report covers operational features (PPID/argument spoofing, API hashing, file-handle duplication), example attack scenarios, detection opportunities (IElevator usage, headless browser instantiation, unauthorized reads of browser SQLite databases), and mitigation recommendations such as using external credential managers and EDR rules targeting the described behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.