logo

Parallel Password Cracker Released for Download

ID: 121481eb-630e-5ded-b20b-0c681555f5f0

STIX ID: report--121481eb-630e-5ded-b20b-0c681555f5f0

Feed Name: Darknet

Threat Score
70/100

Date Published: 2007-11-16

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool aimed at extracting saved credentials, session cookies, OAuth refresh tokens, and other sensitive browser-stored secrets from major Windows browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It implements an App-Bound Encryption bypass for Chromium-based browsers by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface, retrieves DPAPI or NSS-stored keys for other browsers, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, and a custom SQLite parser). The report covers usage, attack scenarios, detection opportunities (process injection, IElevator calls, headless browser instantiation, database reads), red-team relevance, and mitigation recommendations such as using native credential managers and EDR detections that monitor IElevator and headless browser behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.