logo

Avira Joins The Crowd & Starts To Offer Mac Antivirus Software

ID: 17436c4d-b4c7-5b42-859f-da42659271fe

STIX ID: report--17436c4d-b4c7-5b42-859f-da42659271fe

Feed Name: Darknet

Threat Score
75/100

Date Published: 2012-03-29

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool (available as precompiled binaries) that targets major Windows browsers — Chrome, Edge, Brave (App‑Bound Encryption via IElevator COM bypass), Opera/Vivaldi (DPAPI), and Firefox (NSS) — to extract saved credentials, session cookies, OAuth tokens, credit card data and browsing history. The tool uses DLL injection (Early Bird APC) into a headless Chromium process to decrypt app_bound_encrypted_key, includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON, and is positioned for red team/assumed‑breach testing while also presenting a clear malicious capability if misused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.