logo

Hacking Tools, Hacker News & Cyber Security

ID: e372e6d5-0b84-5495-a697-a6ff46a5c97c

STIX ID: report--e372e6d5-0b84-5495-a697-a6ff46a5c97c

Feed Name: Darknet

Threat Score
75/100

Date Published: 2008-10-28

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool targeting major Chromium and Firefox browsers; it extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and history by using techniques including DLL injection (Early Bird APC), spawning headless Chromium to access the IElevator COM interface to decrypt App‑Bound Encryption keys, and DPAPI/NSS handling for other browsers. The report documents installation/usage, supported browsers, evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), a realistic attack scenario for lateral/cloud takeover, detection opportunities (IElevator calls, unusual headless browser processes, reads of browser SQLite DBs), and mitigation guidance for enterprise defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.