logo

Userland Anti-debugging & Anti-detection Rootkit

ID: 1b6c941f-1052-5a28-bf98-ac67178b9543

STIX ID: report--1b6c941f-1052-5a28-bf98-ac67178b9543

Feed Name: Darknet

Threat Score
75/100

Date Published: 2014-02-14

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a Windows post-exploitation tool that extracts credentials and session data from major browsers (Chrome, Edge, Brave, Opera, Vivaldi, Firefox) by bypassing Chrome's App-Bound Encryption with an IElevator COM-based DLL injection technique and handling DPAPI/NSS decryption where applicable; the report details functionality, usage, evasion techniques, detection indicators, and mitigation recommendations for red team and defensive testing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.