logo

Hacking Tools, Hacker News & Cyber Security

ID: b14900df-25db-5aba-88a4-baf9e4cd27f5

STIX ID: report--b14900df-25db-5aba-88a4-baf9e4cd27f5

Feed Name: Darknet

Threat Score
70/100

Date Published: 2016-03-04

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly documented post‑exploitation tool that harvests browser‑stored secrets from major Windows browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, Firefox via NSS). It spawns a headless Chromium process and injects a DLL using Early Bird APC to call the IElevator COM interface and decrypt app_bound_encrypted_key, then parses and decrypts browser SQLite/JSON stores to produce structured JSON output containing cookies, OAuth tokens, saved credentials, autofill data, credit cards and history; the report also lists evasion methods, detection opportunities and mitigations for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.