logo

Hacking Tools, Hacker News & Cyber Security

ID: 7f9f0493-9882-5124-a345-8f96484f444f

STIX ID: report--7f9f0493-9882-5124-a345-8f96484f444f

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-09-02

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a compiled Windows post‑exploitation tool that harvests browser‑stored credentials and tokens (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, Firefox via NSS). It injects a DLL into a headless Chromium process to decrypt the app_bound_encrypted_key using the IElevator COM interface, extracts data from browser SQLite/JSON stores, includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), and outputs structured JSON for red‑team or offensive use, exposing session cookies and OAuth tokens that enable rapid lateral movement and cloud account takeover.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.