logo

Inside Dark Web Exploit Markets in 2025: Pricing, Access & Active Sellers

ID: 1ac65974-6755-5a18-80e8-77b72b573c97

STIX ID: report--1ac65974-6755-5a18-80e8-77b72b573c97

Feed Name: Darknet

Threat Score
72/100

Date Published: 2025-10-01

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a publicly-available post-exploitation tool that harvests browser-stored credentials (cookies, saved logins, OAuth refresh tokens, credit cards, autofill, history, bookmarks) from major Chromium-based browsers and Firefox. It implements an App-Bound Encryption bypass for Chrome/Brave/Edge by spawning a headless Chromium process, performing Early Bird APC DLL injection to call the IElevator COM interface, and returning decrypted keys to decrypt on-disk SQLite/JSON stores; Opera-family browsers use DPAPI extraction and Firefox uses NSS decryption. The report details attack scenarios, operational evasion features, detection signals, and mitigation recommendations for enterprise environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.