logo

AJAX: Is your application secure enough?

ID: 221cd5d7-1edb-5ddb-8670-6e38a38b845c

STIX ID: report--221cd5d7-1edb-5ddb-8670-6e38a38b845c

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-04-05

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a publicly documented post‑exploitation credential‑harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from Chrome, Edge, Brave, Opera/OperaGX/Vivaldi, and Firefox; it bypasses Chrome's App‑Bound Encryption by injecting a DLL into a headless Chromium process using Early Bird APC and the IElevator COM interface, includes DPAPI/NSS handling for other browsers, and implements multiple evasion techniques, with the report covering attack scenarios, detection opportunities, and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.