logo

European Banks Seeing New Wave Of ATM Skimming

ID: 11395b51-89d7-50fe-b21e-65619c3aee1b

STIX ID: report--11395b51-89d7-50fe-b21e-65619c3aee1b

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-11-19

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly documented post‑exploitation tool that harvests browser‑stored secrets (saved logins, session cookies, OAuth tokens, credit cards, autofill, history, bookmarks) from Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox. It implements an App‑Bound Encryption bypass for Chromium browsers by spawning a headless Chromium process and injecting a DLL that invokes the IElevator COM interface to decrypt keys, supports DPAPI and NSS decryption where applicable, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parsing). The report covers usage, attack scenarios, detection opportunities (process injection, headless browser instantiation, IElevator calls, reads of browser SQLite files), and mitigation advice such as moving secrets out of browsers and improving EDR visibility.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.