logo

Hacking Tools, Hacker News & Cyber Security

ID: babfa3ff-f383-5636-941c-9e9a1843f6fb

STIX ID: report--babfa3ff-f383-5636-941c-9e9a1843f6fb

Feed Name: Darknet

Threat Score
75/100

Date Published: 2018-03-11

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials and session tokens from Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox. It uses a DLL injected into a headless Chromium process (Early Bird APC) to leverage the IElevator COM interface and decrypt App-Bound Encryption keys, handles DPAPI and NSS models for other browsers, and includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication). The tool outputs structured JSON suitable for red-team use and can enable rapid lateral movement or cloud account takeover by extracting active session cookies and OAuth tokens; detection focuses on anomalous headless browser processes, unexpected process injection, and non-browser access to browser SQLite databases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.