logo

Collar Bomber Gets Owned By Word Metadata & USB Drive

ID: 298212e7-1aa4-5fb2-850a-beb42e05f05c

STIX ID: report--298212e7-1aa4-5fb2-850a-beb42e05f05c

Feed Name: Darknet

Threat Score
78/100

Date Published: 2011-08-18

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool designed to harvest browser-stored credentials and session tokens from major Windows browsers (Chrome, Edge, Brave, Opera family, Vivaldi, and Firefox). It uses a compiled executable and a DLL to bypass App-Bound Encryption (via spawning a headless Chromium process and IElevator COM calls using Early Bird APC injection) or DPAPI/NSS decryption as appropriate, extracts cookies, saved logins, OAuth refresh tokens, credit cards, autofill data and history, includes evasion techniques to reduce EDR detection, and outputs structured JSON for red team or adversary use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.