logo

Hacking Tools, Hacker News & Cyber Security

ID: a42f9b3f-1f2a-52eb-8903-6564ed829735

STIX ID: report--a42f9b3f-1f2a-52eb-8903-6564ed829735

Feed Name: Darknet

Threat Score
75/100

Date Published: 2015-11-26

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool designed to extract saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from major browsers (Chrome, Edge, Brave, Opera family, Vivaldi, and Firefox). It bypasses Chrome’s App‑Bound Encryption (Chrome 127+) by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface, retrieves DPAPI or NSS secrets for other browsers, and includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection). The tool outputs structured JSON, is positioned for red-team use, and the report details detection opportunities (process injection, IElevator calls, headless browser instantiation, reads of browser SQLite DBs) and mitigations such as using dedicated credential managers and EDR rules targeting IElevator and headless browser behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.