logo

Hacking Tools, Hacker News & Cyber Security

ID: f5be43b5-d6b9-53e5-bad6-16b6c9e1e6f4

STIX ID: report--f5be43b5-d6b9-53e5-bad6-16b6c9e1e6f4

Feed Name: Darknet

Threat Score
75/100

Date Published: 2007-03-14

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a Windows post‑exploitation tool that harvests browser-stored credentials across Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox; it bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process, injecting a DLL via Early Bird APC to use the IElevator COM interface, and decrypts or reads on-disk SQLite/JSON stores to extract cookies, OAuth refresh tokens, saved logins, credit cards, autofill, history and bookmarks, outputting results as JSON. The report describes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), attack scenarios, red-team relevance, and detection/mitigation opportunities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.