logo

Hacking Tools, Hacker News & Cyber Security

ID: ec0ce1db-9ed3-59c8-a618-6d1e65bc9f5a

STIX ID: report--ec0ce1db-9ed3-59c8-a618-6d1e65bc9f5a

Feed Name: Darknet

Threat Score
78/100

Date Published: 2008-11-14

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available Windows post-exploitation tool that harvests credentials and session tokens from Chrome, Edge, Brave, Opera, Vivaldi and Firefox by combining a compiled executable with a DLL injected into a headless Chromium process to bypass App‑Bound Encryption (via the IElevator COM interface) or by extracting DPAPI/NSS-protected secrets. The report details its extraction capabilities (cookies, saved logins, OAuth refresh tokens, credit cards, autofill, history), operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), usage guidance, red‑team relevance, and detection/mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.