logo

Hacking Tools, Hacker News & Cyber Security

ID: d22700c6-e82a-577b-b3e7-15cfb7a1f0ca

STIX ID: report--d22700c6-e82a-577b-b3e7-15cfb7a1f0ca

Feed Name: Darknet

Threat Score
75/100

Date Published: 2013-10-30

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a Windows post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, browsing history, and bookmarks from major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It implements an App-Bound Encryption bypass for Chromium-based browsers by spawning a headless Chromium process, injecting a DLL via Early Bird APC to use the IElevator COM interface to decrypt keys, supports DPAPI and NSS decryption for other browsers, outputs structured JSON, and includes evasion features aimed at reducing EDR detection — enabling rapid credential extraction and potential cloud account takeover from compromised developer endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.