logo

Spoof All Ports Open & Emulate Valid Services

ID: 0ced375d-4e0b-5823-bd5e-243c204a8c3e

STIX ID: report--0ced375d-4e0b-5823-bd5e-243c204a8c3e

Feed Name: Darknet

Threat Score
75/100

Date Published: 2018-04-06

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly distributed post-exploitation tool that harvests browser-stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill, history, bookmarks) from major Chromium- and Gecko-based browsers by using techniques including headless Chromium spawning, Early Bird APC DLL injection to call the IElevator COM interface (bypassing App-Bound Encryption), DPAPI and NSS decryption, and operational evasion (string obfuscation, API hashing, PPID/argument spoofing, handle duplication). The tool outputs structured JSON for red team use and is positioned to demonstrate the realistic blast radius of compromised developer workstations and cloud account takeover risk; detection opportunities and mitigation guidance are included.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.