logo

Hacking Tools, Hacker News & Cyber Security

ID: aad9dff6-5903-5517-b9ee-4e8f41e211ca

STIX ID: report--aad9dff6-5903-5517-b9ee-4e8f41e211ca

Feed Name: Darknet

Threat Score
75/100

Date Published: 2009-04-14

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post‑exploitation credential‑harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks from Chromium‑based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface to decrypt keys, uses DPAPI extraction where applicable, and parses on‑disk SQLite/JSON stores to produce structured JSON output; the tool includes multiple evasion techniques and is intended for red‑team use but presents high abuse potential for lateral movement and cloud account takeover.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.