logo

Twitter Major Password Reset After Phishing Attack

ID: 292ad772-1b54-5da9-9e59-5c1b6a4b085d

STIX ID: report--292ad772-1b54-5da9-9e59-5c1b6a4b085d

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-02-03

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a public post-exploitation tool that extracts browser-stored credentials (cookies, saved logins, OAuth refresh tokens, credit cards, autofill data, history, and bookmarks) from Chromium-based browsers and Firefox on Windows. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface (Early Bird APC injection), handles DPAPI for some Chromium forks and NSS for Firefox, includes evasion features for EDR, and outputs structured JSON for red-team or offensive use while the report outlines detection and mitigation strategies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.