logo

Hacking Tools, Hacker News & Cyber Security

ID: aa8dcfab-ab13-55f6-9fc2-88e756f2400f

STIX ID: report--aa8dcfab-ab13-55f6-9fc2-88e756f2400f

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-09-25

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, history and bookmarks from Chrome/Edge/Brave (via App‑Bound Encryption bypass), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS). It achieves App‑Bound Encryption bypass by spawning a headless Chromium process, injecting a DLL via Early Bird APC to use the IElevator COM interface to decrypt keys, then parses and decrypts on-disk SQLite/JSON stores; the tool includes multiple operational evasion techniques and outputs structured JSON suitable for red-team or malicious reuse, enabling fast account takeover and lateral movement from a single compromised host.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.