logo

Hacking Tools, Hacker News & Cyber Security

ID: 9b46cf5b-d19f-5ff6-94e2-5f1e063dc288

STIX ID: report--9b46cf5b-d19f-5ff6-94e2-5f1e063dc288

Feed Name: Darknet

Threat Score
75/100

Date Published: 2009-04-22

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool for Windows that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from Chromium‑based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox; it bypasses Chrome App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to leverage the IElevator COM interface, and uses DPAPI/NSS methods for other browsers. The tool includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, file‑handle duplication), outputs structured JSON, and is framed for red‑team assumed‑breach testing but represents a high‑impact capability for real-world credential theft and cloud account takeover. Detection opportunities and mitigations (monitoring IElevator calls, headless browser instantiation, and moving secrets out of browsers) are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.