logo

Hacking Tools, Hacker News & Cyber Security

ID: 9b057cda-0bae-5713-bec9-22e34a009957

STIX ID: report--9b057cda-0bae-5713-bec9-22e34a009957

Feed Name: Darknet

Threat Score
70/100

Date Published: 2009-05-11

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly released Windows post-exploitation tool that harvests credentials and session data from major browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It uses headless Chromium process injection (Early Bird APC + IElevator COM) to decrypt app_bound_encrypted_key, includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is useful for red teams or adversaries seeking rapid lateral movement and cloud account takeover from compromised developer workstations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.