logo

Hacking Tools, Hacker News & Cyber Security

ID: 889bb66e-3a3e-54d3-b232-68e17aa84a75

STIX ID: report--889bb66e-3a3e-54d3-b232-68e17aa84a75

Feed Name: Darknet

Threat Score
72/100

Date Published: 2017-10-03

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that targets major Windows browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS) to extract passwords, session cookies, OAuth tokens, credit cards, autofill data and history. It uses headless Chromium spawning with DLL injection (Early Bird APC) to call the IElevator COM interface and decrypt app_bound_encrypted_key, includes multiple evasion techniques to reduce EDR detection, outputs structured JSON, and is positioned for red‑team/assumed‑breach testing while representing a high‑impact capability if abused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.