logo

Post-Mortem Data Destruction

ID: 0d0d941c-c630-59ed-a942-9f41f06b881d

STIX ID: report--0d0d941c-c630-59ed-a942-9f41f06b881d

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-03-10

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a post-exploitation tool that harvests browser-stored credentials (passwords, cookies, OAuth tokens, credit cards, autofill data, history) from major Windows browsers. It bypasses Chrome’s App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt keys, handles DPAPI and NSS decryption for other browsers, includes multiple evasion techniques, and is positioned for red-team assumed-breach testing rather than exfiltration to C2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.