logo

Hacking Tools, Hacker News & Cyber Security

ID: b24cf519-8e3c-5c67-9825-35e52700beff

STIX ID: report--b24cf519-8e3c-5c67-9825-35e52700beff

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-02-26

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, and history from Chromium-based and Gecko-based browsers on Windows. It bypasses Chrome’s App-Bound Encryption by injecting a DLL into a headless Chromium process to call the IElevator COM interface, retrieves DPAPI keys for some Chromium forks, handles Firefox NSS decryption directly, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication, and a custom SQLite parser). The tool is aimed at red team/assumed-breach testing but demonstrates a high-risk technique for lateral movement and cloud account takeover if used by malicious actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.