logo

Hacking Tools, Hacker News & Cyber Security

ID: d6ffb405-71d3-546b-af1a-e3fa2f5473ca

STIX ID: report--d6ffb405-71d3-546b-af1a-e3fa2f5473ca

Feed Name: Darknet

Threat Score
70/100

Date Published: 2015-11-20

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a Windows post‑exploitation credential‑harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card details and browsing data from Chromium‑based and Gecko‑based browsers; it bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface, and uses DPAPI or NSS techniques for other browsers. The report details technical tradecraft (Early Bird APC injection, handle duplication, API hashing, PPID/argument spoofing), operational usage, detection opportunities, and its value for red teams testing credential exposure on compromised developer workstations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.