logo

Hacking Tools, Hacker News & Cyber Security

ID: a015ffbb-38d3-557a-8f08-75d4e23279fb

STIX ID: report--a015ffbb-38d3-557a-8f08-75d4e23279fb

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-07-30

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a precompiled Windows post-exploitation tool that harvests browser-stored credentials and session data from Chromium-based (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox browsers. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt keys, also handling DPAPI and NSS models for other browsers; extracted artifacts (cookies, OAuth refresh tokens, saved logins, autofill, credit cards, history) are output as JSON. The report describes operational features (PPID/argument spoofing, API hashing, file-handle duplication), attack scenarios enabling cloud account takeover and lateral movement from developer workstations, and recommends detection opportunities and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.