logo

Hacking Tools, Hacker News & Cyber Security

ID: 95466c09-7245-53f3-8870-2bab9e3c6e96

STIX ID: report--95466c09-7245-53f3-8870-2bab9e3c6e96

Feed Name: Darknet

Threat Score
75/100

Date Published: 2011-06-20

Date Updated: 2026-05-18

...
...

DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser‑stored credentials and session data across Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox; it includes an App‑Bound Encryption bypass for Chromium browsers (using headless process spawn + DLL injection and the IElevator COM interface) and extracts cookies, saved logins, OAuth refresh tokens, credit cards, autofill data, and history into JSON output. The report describes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), an example attack scenario demonstrating rapid cloud/SaaS account takeover potential, and detection/mitigation recommendations focused on monitoring IElevator usage, headless browser instantiation, and restricting browser-stored secrets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.