logo

Sububy – A Modular Ruby Suite for Subdomain Enumeration

ID: 1c78019a-9b10-590c-97ca-853c25664660

STIX ID: report--1c78019a-9b10-590c-97ca-853c25664660

Feed Name: Darknet

Threat Score
75/100

Date Published: 2025-06-27

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a publicly documented post-exploitation tool designed to harvest browser-stored credentials and session tokens from major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It bypasses App-Bound Encryption in modern Chromium builds by spawning a headless browser and injecting a DLL via Early Bird APC to call the IElevator COM interface, supports DPAPI and NSS decryption where applicable, outputs structured JSON of extracted secrets, and includes operational evasion features aimed at reducing EDR detection—posing a high-risk capability for lateral movement and cloud account takeover in compromised Windows environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.