logo

Hacking Tools, Hacker News & Cyber Security

ID: 7e51d144-2015-5e97-baaf-923d168c6b4f

STIX ID: report--7e51d144-2015-5e97-baaf-923d168c6b4f

Feed Name: Darknet

Threat Score
72/100

Date Published: 2016-06-25

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts browser-stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill data, history, and bookmarks) from Chrome, Edge, Brave (App-Bound Encryption bypass via IElevator DLL injection), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS). The report covers technical implementation, usage examples, evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection), detection opportunities, and mitigation advice, and positions the tool as a red-team-focused but potentially abusable capability for rapid account takeover and lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.