logo

Google Native Client Security/Hacking Contest

ID: 256017b9-987b-59a2-bb75-7ef374dce3c9

STIX ID: report--256017b9-987b-59a2-bb75-7ef374dce3c9

Feed Name: Darknet

Threat Score
78/100

Date Published: 2009-03-09

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a precompiled Windows post-exploitation tool that harvests credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from Chromium-based and Firefox browsers by bypassing App-Bound Encryption (via injection into a headless Chromium process and use of the IElevator COM interface) and handling DPAPI/NSS models for other browsers; it includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication) and outputs structured JSON for rapid credential reuse, enabling fast lateral movement and cloud account takeover. The report includes a usage example, an attack scenario, detection opportunities (monitoring IElevator calls, unusual headless browser instantiation, reads of browser SQLite DBs by non-browser processes), and mitigation advice such as using external credential managers and EDR rules focused on the described behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.