logo

Hacking Tools, Hacker News & Cyber Security

ID: f7245c9a-29d1-5460-967e-4658e4932b80

STIX ID: report--f7245c9a-29d1-5460-967e-4658e4932b80

Feed Name: Darknet

Threat Score
75/100

Date Published: 2014-12-12

Date Updated: 2026-05-18

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card numbers, autofill data and browsing history from major browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, Firefox). It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL that uses the IElevator COM interface to decrypt the app_bound_encrypted_key, handles DPAPI/NSS for other browsers, includes multiple EDR-evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication), and outputs structured JSON for red-team or adversary use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.