logo

Hacking Tools, Hacker News & Cyber Security

ID: 7f4ee284-5a67-5208-be5f-2ebeb4564403

STIX ID: report--7f4ee284-5a67-5208-be5f-2ebeb4564403

Feed Name: Darknet

Threat Score
75/100

Date Published: 2016-12-13

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a pre-compiled Windows post-exploitation tool that extracts browser-stored credentials and session tokens from major Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It bypasses App-Bound Encryption in modern Chromium builds by spawning a headless Chromium process and injecting a DLL (Early Bird APC) to call the IElevator COM interface, retrieves DPAPI/NSS keys where applicable, parses on-disk SQLite/JSON stores, and outputs structured JSON. The tool includes operational evasion (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser) making it relevant for red-team testing and a potentially high-impact capability for real attackers seeking cloud account takeover or lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.