logo

Hacking Tools, Hacker News & Cyber Security

ID: d8862a7b-5023-58cc-ad01-11e40f83a620

STIX ID: report--d8862a7b-5023-58cc-ad01-11e40f83a620

Feed Name: Darknet

Threat Score
75/100

Date Published: 2007-11-06

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major Windows browsers (Chrome/Edge/Brave via App-Bound Encryption bypass; Opera/Vivaldi via DPAPI; Firefox via NSS). It uses a headless Chromium process with Early Bird APC DLL injection and the IElevator COM interface to decrypt app-bound keys, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and outputs structured JSON for red team use; the report also outlines attack scenarios, detection opportunities, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.