logo

A tool for parsing and decrypting MS-CHAPv2 network handshakes.

ID: fe0dc51e-918b-5c5f-83d3-b0314d0d10ff

STIX ID: report--fe0dc51e-918b-5c5f-83d3-b0314d0d10ff

Feed Name: Darknet

Threat Score
75/100

Date Published: 2012-08-08

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major browsers (Chrome/Edge/Brave via App-Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). The tool uses headless Chromium with Early Bird APC DLL injection and the IElevator COM interface to decrypt app-bound keys, includes operational evasion (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and outputs structured JSON for red team use; the repo describes usage, an attack scenario, and detection/mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.