logo

L0phtcrack LC5 Password Cracking Alternative

ID: ac86dab5-2042-5265-8bb8-ea86e02a646a

STIX ID: report--ac86dab5-2042-5265-8bb8-ea86e02a646a

Feed Name: Darknet

Threat Score
78/100

Date Published: 2006-09-10

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool for Windows that harvests browser-stored secrets (saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill data, and history) from Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium instance and injecting a DLL via Early Bird APC to invoke the IElevator COM interface to decrypt keys, uses DPAPI extraction for some browsers and NSS handling for Firefox, and includes multiple operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication). Output is structured JSON, the tool is intended for red-team/assumed-breach testing but poses a high-risk capability for lateral movement and cloud account takeover if used by adversaries; the report also outlines detection signals and mitigations such as monitoring IElevator usage, headless browser instantiation, and limiting browser-stored secrets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.