logo

Stuxnet 2 Under Development By Spy Agencies?

ID: 09a8a5b0-3516-5e49-a8a9-dac5970c5a05

STIX ID: report--09a8a5b0-3516-5e49-a8a9-dac5970c5a05

Feed Name: Darknet

Threat Score
75/100

Date Published: 2013-12-03

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that targets Chromium‑based and Gecko browsers on Windows to extract saved passwords, cookies, OAuth refresh tokens, credit cards, autofill and history. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL (Early Bird APC) to call the IElevator COM interface, retrieves DPAPI or NSS keys for other browsers, outputs structured JSON, and includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication). The report highlights red team relevance, attack scenarios, detection opportunities (unexpected process injection, IElevator calls, reads of browser SQLite DBs), and mitigation advice such as using external credential managers and EDR rules that monitor IElevator usage or headless browser behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.