logo

Hacking Tools, Hacker News & Cyber Security

ID: fcd35d76-8077-54b5-99fd-ca6e43799f71

STIX ID: report--fcd35d76-8077-54b5-99fd-ca6e43799f71

Feed Name: Darknet

Threat Score
75/100

Date Published: 2007-03-26

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card details, autofill data and browsing history from major browsers (Chrome, Edge, Brave, Opera/Opera GX, Vivaldi, Firefox). It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt the app_bound_encrypted_key; it handles DPAPI and NSS-based encryption for other browsers, writes structured JSON output, and includes multiple operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser). The report highlights high impact risks for compromised developer endpoints (cloud account takeover, lateral movement, persistent SaaS access), detection opportunities (injection, IElevator calls, reads of browser SQLite files) and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.