logo

Hacking Tools, Hacker News & Cyber Security

ID: 8ebbf2b7-933e-5ea8-b698-6684b226d69c

STIX ID: report--8ebbf2b7-933e-5ea8-b698-6684b226d69c

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-06-03

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a Windows post-exploitation tool that harvests saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from Chromium-based (Chrome, Edge, Brave, Opera, Vivaldi) and Firefox browsers. The report explains the tool's architecture—an executable plus a DLL that uses Early Bird APC injection to run inside a headless Chromium process and call the IElevator COM interface to decrypt App-Bound Encryption keys—handling DPAPI and NSS models where applicable. It describes operational evasion features, usage examples, an assumed-breach attack scenario demonstrating rapid credential extraction and session replay potential, and detection/mitigation recommendations for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.