logo

Google Poisoning Attack Gumblar Still Causing Problems

ID: 0ab6623a-8080-540b-a2c9-5aca6ddc579f

STIX ID: report--0ab6623a-8080-540b-a2c9-5aca6ddc579f

Feed Name: Darknet

Threat Score
75/100

Date Published: 2009-05-20

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a public post-exploitation credential-harvesting tool that extracts saved passwords, cookies, OAuth refresh tokens, credit cards and browsing data from major browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, Firefox via NSS). It uses Early Bird APC DLL injection into a headless Chromium process to call the IElevator COM interface and decrypt app_bound_encrypted_key, includes several EDR-evasion features, outputs structured JSON for red‑team use, and the report covers attack scenarios, detection opportunities, and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.