logo

ARP Handler Detect and Block ARP Poisoning/Spoofing

ID: 024c424e-9c06-5b92-b621-c6a5e3897dd0

STIX ID: report--024c424e-9c06-5b92-b621-c6a5e3897dd0

Feed Name: Darknet

Threat Score
75/100

Date Published: 2008-06-16

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a publicly documented post-exploitation tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks from major Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and using DLL injection plus the IElevator COM interface to decrypt keys, includes DPAPI and NSS handling for other browsers, and implements multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parsing). The tool is positioned for red-team/assumed-breach testing but represents a high-risk capability for lateral movement and cloud account takeover if used by malicious actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.