logo

Hacking Tools, Hacker News & Cyber Security

ID: fa6db515-5aac-5918-9ec9-9848ce6c0917

STIX ID: report--fa6db515-5aac-5918-9ec9-9848ce6c0917

Feed Name: Darknet

Threat Score
75/100

Date Published: 2018-07-07

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts browser‑stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill, and history) from Chrome, Edge, Brave, Opera family, Vivaldi, and Firefox. It implements an App‑Bound Encryption bypass for Chromium-based browsers by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt the app_bound_encrypted_key, handles DPAPI and NSS decryption for other browsers, includes operational evasion features, and provides usage, detection opportunities, and mitigation recommendations for red‑team and defensive testing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.