logo

Hacking Tools, Hacker News & Cyber Security

ID: d5277ca6-b674-53e1-a87e-b2a09861e652

STIX ID: report--d5277ca6-b674-53e1-a87e-b2a09861e652

Feed Name: Darknet

Threat Score
75/100

Date Published: 2008-06-26

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major Windows browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It bypasses Chromium App‑Bound Encryption (Chrome 127+) by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt the app_bound_encrypted_key, uses DPAPI and NSS approaches where appropriate, includes multiple operational evasion features, and outputs structured JSON for red‑team or offensive use; the report includes attack scenarios, detection opportunities, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.