logo

Acunetix Web Vulnerability Scanner v11 Released

ID: 0bd53d55-01f5-5236-b4b2-393938cb2b49

STIX ID: report--0bd53d55-01f5-5236-b4b2-393938cb2b49

Feed Name: Darknet

Threat Score
75/100

Date Published: 2016-11-23

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a publicly documented post‑exploitation tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and history from Chrome, Edge, Brave, Opera (and variants), Vivaldi, and Firefox on Windows. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface, uses DPAPI/NSS decryption for other browsers, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, file handle duplication, custom SQLite parser), outputs structured JSON, and is positioned for red‑team/assumed‑breach testing while highlighting detection and mitigation strategies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.