logo

Hacking Tools, Hacker News & Cyber Security

ID: c16a18a3-469d-53ee-b281-728701bb0468

STIX ID: report--c16a18a3-469d-53ee-b281-728701bb0468

Feed Name: Darknet

Threat Score
70/100

Date Published: 2016-09-29

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and history from Chromium‑based and Gecko browsers on Windows. It bypasses Chrome's App‑Bound Encryption (Chrome 127+) by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt the app_bound_encrypted_key, retrieves DPAPI keys for some browsers and uses NSS decryption for Firefox; the tool includes multiple operational evasion features and outputs structured JSON for red‑team or adversary use, with detection guidance and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.