logo

Shelling our way up

ID: 0cada1f1-1e45-57fe-8d24-f5cb27023878

STIX ID: report--0cada1f1-1e45-57fe-8d24-f5cb27023878

Feed Name: Darknet

Threat Score
75/100

Date Published: 2008-04-21

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from Chromium‑based and Gecko browsers on Windows. The tool implements an App‑Bound Encryption bypass (using a headless Chromium process, Early Bird APC DLL injection and the IElevator COM interface) as well as DPAPI and NSS extraction paths for other browsers, includes multiple evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and outputs structured JSON to facilitate credential reuse; the report also outlines detection points and mitigations such as monitoring IElevator calls, headless browser instantiation, and moving secrets out of browsers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.