logo

Hacking Tools, Hacker News & Cyber Security

ID: c6c4795f-3170-5e54-a109-c9335f9a586c

STIX ID: report--c6c4795f-3170-5e54-a109-c9335f9a586c

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-07-05

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, and browsing history from major browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, Firefox). It bypasses Chrome's App‑Bound Encryption by injecting a DLL into a headless Chromium process to use the IElevator COM interface, supports DPAPI and NSS decryption paths, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, file handle duplication), and is distributed as a precompiled Windows executable intended for red-team/assumed‑breach testing but presenting a significant abuse risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.