Hacking Tools, Hacker News & Cyber Security
ID: e057e243-abce-59b8-9c86-c793ff0bd4c1
STIX ID: report--e057e243-abce-59b8-9c86-c793ff0bd4c1
Feed Name: Darknet
**DumpBrowserSecrets** is a post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card numbers, autofill data, and browsing history from major Chromium-based browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi) and Firefox; it bypasses Chrome App-Bound Encryption by injecting a DLL into a headless Chromium process via Early Bird APC and using the IElevator COM interface, and handles DPAPI/NSS for other browsers. The precompiled Windows executable includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication) and outputs structured JSON for red-team use, but its capabilities also present a high-risk credential-theft vector if abused by malicious actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
