logo

Wordpress Download Server Compromised (2.1.1)

ID: 10acf912-6eec-50db-869a-03b5e0720996

STIX ID: report--10acf912-6eec-50db-869a-03b5e0720996

Feed Name: Darknet

Threat Score
75/100

Date Published: 2007-03-05

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly released post-exploitation credential-harvesting tool designed to extract saved credentials, session cookies, OAuth tokens, credit card data, autofill entries, and browsing history from major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It bypasses Chrome's App-Bound Encryption by injecting a DLL into a spawned headless Chromium process (Early Bird APC + IElevator COM), handles DPAPI and NSS cases appropriately, includes multiple operational evasion features, outputs structured JSON, and is positioned as a red-team tool to demonstrate SaaS and browser-based credential risk on compromised Windows hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.