eEye Launches 0-Day Exploit Tracker
ID: 159bef03-07cd-5ceb-afe4-0b7b4ac92cef
STIX ID: report--159bef03-07cd-5ceb-afe4-0b7b4ac92cef
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests credentials and session tokens from major Windows browsers (Chrome, Edge, Brave, Opera family, Vivaldi, and Firefox). It bypasses App-Bound Encryption in Chromium-based browsers by injecting a DLL into a headless browser process to access the IElevator COM interface, retrieves DPAPI/NSS-protected secrets where applicable, outputs structured JSON of recovered credentials and tokens, and includes operational evasion features aimed at reducing EDR detection — making it a high-risk red-team/abuse-capable infostealer for compromised developer or workstation endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
