logo

Hacking Tools, Hacker News & Cyber Security

ID: b501c655-5787-5d71-a98d-3f4b52cc809a

STIX ID: report--b501c655-5787-5d71-a98d-3f4b52cc809a

Feed Name: Darknet

Threat Score
70/100

Date Published: 2007-12-18

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly documented post‑exploitation tool that harvests browser‑stored credentials and session tokens from major Windows browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). The tool uses headless Chromium process spawning and Early Bird APC DLL injection to call the IElevator COM interface and decrypt app_bound_encrypted_key, then reads and decrypts browser SQLite/JSON stores to output structured JSON containing cookies, OAuth refresh tokens, saved logins, credit cards, autofill and history; it includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication) and is presented as a red team utility while being relevant to real-world credential theft scenarios.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.