logo

Multi-Purpose Application Input Fuzzing Tool

ID: 071b7fb0-ef3a-584c-853a-c176bdda6b89

STIX ID: report--071b7fb0-ef3a-584c-853a-c176bdda6b89

Feed Name: Darknet

Threat Score
75/100

Date Published: 2015-05-25

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly released post‑exploitation tool that harvests browser-stored credentials and session tokens from major Windows browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It bypasses Chrome’s App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL that uses the IElevator COM interface to decrypt keys, uses DPAPI or NSS where applicable, and writes structured JSON output; the tool includes multiple operational evasion techniques and is intended for red team/assumed‑breach testing but represents a realistic threat to credential and SaaS account security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.