logo

Hacking Tools, Hacker News & Cyber Security

ID: ec6cbe7e-b8fe-53aa-a45b-0ac54bffec37

STIX ID: report--ec6cbe7e-b8fe-53aa-a45b-0ac54bffec37

Feed Name: Darknet

Threat Score
75/100

Date Published: 2009-04-23

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts saved passwords, cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks from Chrome, Edge, Brave, Opera family, Vivaldi, and Firefox. It implements an IElevator COM-based App‑Bound Encryption bypass for Chromium 127+ by injecting a DLL into a headless browser via Early Bird APC, retrieves decryption keys (or DPAPI/NSS keys where applicable), and writes structured JSON output; the tool includes multiple evasion techniques and is intended for assumed‑breach/red team use but demonstrates a high‑impact capability for account takeover and lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.