logo

Hacking Tools, Hacker News & Cyber Security

ID: a950207f-012f-56c8-a1aa-0ccefdd92262

STIX ID: report--a950207f-012f-56c8-a1aa-0ccefdd92262

Feed Name: Darknet

Threat Score
75/100

Date Published: 2008-09-25

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets major Windows browsers (Chrome/Edge/Brave via an App-Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS) to extract saved passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, and browsing history. It uses Early Bird APC DLL injection into a headless Chromium process to access the IElevator COM interface and decrypt app_bound_encrypted_key, includes operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), and outputs structured JSON for red-team or adversary use; the report also outlines detection opportunities and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.