logo

Google ‘99.9%’ Certain To Shut Down Google.cn

ID: 0ed7e599-d51c-568c-9ee2-42e46a755a40

STIX ID: report--0ed7e599-d51c-568c-9ee2-42e46a755a40

Feed Name: Darknet

Threat Score
80/100

Date Published: 2010-03-15

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a publicly documented post‑exploitation credential‑harvesting tool that extracts passwords, cookies, OAuth refresh tokens, credit card data, autofill entries, and history from major Chromium and Gecko browsers on Windows. It implements a DLL injection into a headless Chromium process to bypass Chrome's App‑Bound Encryption (via the IElevator COM interface), handles DPAPI and NSS decryption for other browsers, includes operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, file‑handle duplication, custom SQLite parser), outputs structured JSON, completes extraction rapidly (<30s in tests), and is intended for red team use but represents an operationally relevant threat to enterprise environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.