logo

U.S. State Department Hacked

ID: 29929625-3fcb-5909-b10e-fcac6ae5817b

STIX ID: report--29929625-3fcb-5909-b10e-fcac6ae5817b

Feed Name: Darknet

Threat Score
75/100

Date Published: 2014-11-18

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post‑exploitation credential‑harvesting tool (from Maldev Academy) that extracts browser‑stored secrets across Chromium and Gecko browsers. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface and retrieve decryption keys, handles DPAPI and NSS models for other browsers, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, and a custom SQLite parser). The tool outputs structured JSON and is positioned for red team/assumed‑breach use, but the described capabilities also represent a realistic offensive capability for credential theft, session replay, and cloud account takeover unless detected or mitigated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.