logo

Hacking Tools, Hacker News & Cyber Security

ID: b8eb26e3-c1be-5ce9-85bb-f3a451714916

STIX ID: report--b8eb26e3-c1be-5ce9-85bb-f3a451714916

Feed Name: Darknet

Threat Score
75/100

Date Published: 2008-01-01

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly distributed Windows post‑exploitation tool that harvests browser‑stored credentials and tokens from Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox. It bypasses Chrome’s App‑Bound Encryption (Chrome 127+) by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface to decrypt keys, and it uses DPAPI or NSS decryption where applicable; extracted data (cookies, saved logins, OAuth refresh tokens, autofill, credit cards, history, bookmarks) is exported as JSON. The report documents operational evasion techniques, a sample attack scenario, detection points (process injection, IElevator calls, reads of browser SQLite files), and mitigation recommendations such as using dedicated credential managers and EDR rules that monitor browser COM usage and headless browser instantiation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.