logo

Defense Workers Warned About Spy Coins for Espionage

ID: 0b7553b2-435f-552d-91a5-c46772818e86

STIX ID: report--0b7553b2-435f-552d-91a5-c46772818e86

Feed Name: Darknet

Threat Score
75/100

Date Published: 2007-02-24

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests browser-stored secrets (passwords, session cookies, OAuth refresh tokens, credit cards, autofill and history) from Chromium-based and Firefox browsers on Windows. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL (via Early Bird APC) to call the IElevator COM interface to decrypt the app_bound_encrypted_key, retrieves DPAPI keys for some Chromium forks, or uses NSS decryption for Firefox; outputs structured JSON and includes several operational evasion features intended for red-team use and defensive testing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.