logo

Hacking Tools, Hacker News & Cyber Security

ID: 97b5a3f6-9987-570f-97f3-32cb36495144

STIX ID: report--97b5a3f6-9987-570f-97f3-32cb36495144

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-12-18

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post-exploitation tool that harvests saved credentials and session artifacts from major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, Firefox). It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface, returns decrypted keys to the executable, and parses on-disk SQLite/JSON stores to extract passwords, cookies, OAuth refresh tokens, credit cards, autofill, history, and bookmarks. The tool includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication, custom SQLite parser), outputs structured JSON, and is positioned for red-team assumed-breach use while clearly enabling high-impact credential theft and cloud account takeover if abused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.