logo

Hacking Tools, Hacker News & Cyber Security

ID: 8a25dd4c-c972-5d50-935a-cad4287ca425

STIX ID: report--8a25dd4c-c972-5d50-935a-cad4287ca425

Feed Name: Darknet

Threat Score
78/100

Date Published: 2015-06-13

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that targets major Windows browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox) to extract saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL that uses the IElevator COM interface (via Early Bird APC injection) to decrypt the app_bound_encrypted_key, retrieves DPAPI keys for some Chromium forks, and directly handles Firefox NSS decryption; the tool includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication, and a custom SQLite parser) and is presented with usage, detection opportunities, and mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.