logo

Hacking Tools, Hacker News & Cyber Security

ID: b83bed47-c237-583a-adaf-5340fc6a9124

STIX ID: report--b83bed47-c237-583a-adaf-5340fc6a9124

Feed Name: Darknet

Threat Score
75/100

Date Published: 2008-07-28

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly documented post-exploitation credential extraction tool that targets Chromium-based (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox browsers on Windows. It uses a compiled executable and a DLL that is injected into a headless Chromium process to bypass App-Bound Encryption via the IElevator COM interface (Early Bird APC injection) and decrypts browser-stored secrets (cookies, saved logins, OAuth refresh tokens, credit cards, autofill, history). The tool includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, and a custom SQLite parser), outputs structured JSON of recovered data, and is presented as a red-team utility for assessing exposure of browser-stored credentials and endpoint controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.