logo

Boffins Crack OpenSSL Library Using Power Fluctuations

ID: 0601f86a-0b25-5a94-a949-c344afc74ad0

STIX ID: report--0601f86a-0b25-5a94-a949-c344afc74ad0

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-03-04

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a Windows post‑exploitation tool that harvests credentials and session artifacts from major Chromium- and Gecko-based browsers by bypassing App‑Bound Encryption (via IElevator COM inside an injected DLL in a headless Chromium process), extracting DPAPI and NSS-protected data, and writing structured JSON output; it supports Chrome, Edge, Brave, Opera/Opera GX, Vivaldi and Firefox and includes multiple evasion features aimed at reducing EDR detection. The tool enables rapid credential-driven lateral movement and cloud account takeover on compromised developer endpoints and is intended for red-team/assumed-breach use but presents significant abuse potential if used by malicious actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.