logo

Passive Sniffer & Packet Analysis Tool for Windows

ID: 0272a30f-42cc-5b16-95ee-981b0c1170e0

STIX ID: report--0272a30f-42cc-5b16-95ee-981b0c1170e0

Feed Name: Darknet

Threat Score
75/100

Date Published: 2008-02-27

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials and session tokens from major Chromium-based and Firefox browsers. It implements an App-Bound Encryption bypass for Chrome/Edge/Brave by injecting a DLL into a headless Chromium process (Early Bird APC + IElevator COM) to retrieve encryption keys, uses DPAPI extraction for Opera/Vivaldi variants and NSS decryption for Firefox, and outputs structured JSON. The report covers implementation details, evasion techniques, a realistic attack scenario demonstrating rapid credential extraction and session replay risk, and detection/mitigation recommendations for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.