logo

E-mail Scammers Target Microsoft Users

ID: 0e321fae-f6b4-5454-be55-fcf8bb3728b2

STIX ID: report--0e321fae-f6b4-5454-be55-fcf8bb3728b2

Feed Name: Darknet

Threat Score
76/100

Date Published: 2008-10-16

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a post‑exploitation credential-harvesting tool that extracts browser-stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill, history) from Chrome/Edge/Brave (App‑Bound Encryption bypass via IElevator), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS). It uses DLL injection into a headless Chromium process to decrypt app_bound_encrypted_key, parses on-disk SQLite/JSON stores, outputs structured JSON, includes evasion techniques for EDR, and provides detection and mitigation guidance for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.