logo

Hacking Tools, Hacker News & Cyber Security

ID: 8e203347-6e06-53a1-b639-7cba59a32f18

STIX ID: report--8e203347-6e06-53a1-b639-7cba59a32f18

Feed Name: Darknet

Threat Score
75/100

Date Published: 2016-12-23

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests credentials and session tokens from major browsers (Chrome, Edge, Brave, Opera family, Vivaldi, Firefox). It implements an App-Bound Encryption bypass for Chromium-based browsers by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt the app_bound_encrypted_key, supports DPAPI and NSS decryption for other browsers, and includes operational evasion features; outputs structured JSON of extracted secrets and is intended for red team / assumed-breach use but represents a high-risk capability for real-world account takeover and lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.