logo

Hacking Tools, Hacker News & Cyber Security

ID: b56f8a3a-8b1c-5de5-b341-a354d15bd931

STIX ID: report--b56f8a3a-8b1c-5de5-b341-a354d15bd931

Feed Name: Darknet

Threat Score
75/100

Date Published: 2014-05-22

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets Chromium-based browsers (Chrome, Edge, Brave) and Gecko-based Firefox on Windows to extract saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, history and bookmarks. The report details a technical App-Bound Encryption bypass for Chrome 127+ by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface to decrypt the app_bound_encrypted_key, covers DPAPI/NSS handling for other browsers, lists evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), provides usage and attack scenarios, and recommends detection and mitigation approaches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.