logo

Hacking Tools, Hacker News & Cyber Security

ID: f3f91d1a-c624-5998-9344-ab49a4f82a8a

STIX ID: report--f3f91d1a-c624-5998-9344-ab49a4f82a8a

Feed Name: Darknet

Threat Score
75/100

Date Published: 2017-03-20

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials and session artifacts from Windows endpoints (Chrome/Edge/Brave via an App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It uses DLL injection into a headless Chromium process (Early Bird APC + IElevator COM) to decrypt app_bound_encrypted_key, includes evasion measures (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON of recovered secrets, and is positioned for red-team assumed-breach use but carries clear offensive value for account takeover and lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.