logo

March Commenter of the Month Competition Winner!

ID: 17c3053e-8cc6-5bbd-a3e9-268bb71c5356

STIX ID: report--17c3053e-8cc6-5bbd-a3e9-268bb71c5356

Feed Name: Darknet

Threat Score
75/100

Date Published: 2008-04-07

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly documented post‑exploitation credential‑harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from major Chromium‑based and Firefox browsers. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt the app_bound_encrypted_key, handles DPAPI and NSS models for other browsers, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON, and is targeted at red team/assumed‑breach exercises while also highlighting detection and mitigation strategies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.