logo

Charlie Miller Does It Again At PWN2OWN

ID: 1d8833bd-4764-572f-b981-2ab94fbd3ffd

STIX ID: report--1d8833bd-4764-572f-b981-2ab94fbd3ffd

Feed Name: Darknet

Threat Score
80/100

Date Published: 2009-03-24

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored credentials (cookies, saved logins, OAuth refresh tokens, credit cards, autofill, history, bookmarks) from Chrome, Edge, Brave, Opera variants, Vivaldi and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface, handles DPAPI and NSS where applicable, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and outputs structured JSON for red-team or adversary use; the report includes detection and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.