logo

Hacking Tools, Hacker News & Cyber Security

ID: d37dd590-cc65-597e-8dcc-a73a4ff07dcc

STIX ID: report--d37dd590-cc65-597e-8dcc-a73a4ff07dcc

Feed Name: Darknet

Threat Score
75/100

Date Published: 2007-10-23

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post-exploitation credential-harvesting tool that extracts browser-stored secrets (cookies, saved logins, OAuth refresh tokens, credit cards, autofill and history) from Chrome/Edge/Brave (via an App-Bound Encryption/IElevator bypass using Early Bird APC DLL injection), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS). The tool outputs structured JSON, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parsing), and is described for red-team assumed-breach testing but can enable rapid lateral movement and cloud account takeover; the report also documents detection signals and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.