logo

Hacking Tools, Hacker News & Cyber Security

ID: beafac82-028d-5f67-8bfd-e9e851a0e511

STIX ID: report--beafac82-028d-5f67-8bfd-e9e851a0e511

Feed Name: Darknet

Threat Score
75/100

Date Published: 2017-01-23

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a precompiled Windows post-exploitation tool that harvests browser-stored secrets (passwords, cookies, OAuth refresh tokens, credit card numbers, autofill data, history, bookmarks) from major Chromium-based and Firefox browsers. It bypasses Chrome's App-Bound Encryption (Chrome 127+) by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt the app_bound_encrypted_key; it handles DPAPI and NSS decryption for other browsers, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is positioned for red-team assumed-breach assessments though it embodies capabilities typical of infostealer malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.