logo

Hacking Tools, Hacker News & Cyber Security

ID: b268bbf7-57b6-5ee2-969d-0b9306e6b44a

STIX ID: report--b268bbf7-57b6-5ee2-969d-0b9306e6b44a

Feed Name: Darknet

Threat Score
70/100

Date Published: 2015-02-11

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post‑exploitation credential‑harvesting tool that targets major Chromium and Gecko browsers to extract saved passwords, cookies, OAuth refresh tokens, credit card data, autofill entries, and history. It implements an App‑Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface, uses DPAPI extraction for Opera/Vivaldi variants, and NSS decryption for Firefox; output is structured JSON. The report covers operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), detection opportunities (injection into browser processes, IElevator calls, unauthorized reads of browser SQLite files), and mitigation advice such as using external credential managers and EDRs that monitor browser COM/behavioral anomalies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.