logo

Hacking Tools, Hacker News & Cyber Security

ID: f813493d-c06e-5395-90bf-ba5d7e335182

STIX ID: report--f813493d-c06e-5395-90bf-ba5d7e335182

Feed Name: Darknet

Threat Score
75/100

Date Published: 2016-03-21

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation browser credential‑harvesting tool that targets Chromium‑based (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox browsers to extract passwords, cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface, handles DPAPI for some browsers and NSS for Firefox, and includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication). The write‑up covers usage, attack scenarios, detection opportunities (abnormal process injection, headless browser instantiation, IElevator calls, reads of browser SQLite DBs), and mitigation advice for enterprise defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.