logo

Kyrgyzstan Taken Offline by Huge Denial of Service Attack

ID: 2c745e97-2074-5e09-8e58-d967636629ad

STIX ID: report--2c745e97-2074-5e09-8e58-d967636629ad

Feed Name: Darknet

Threat Score
75/100

Date Published: 2009-01-29

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post-exploitation credential-harvesting tool that extracts browser-stored secrets (saved logins, cookies, OAuth tokens, credit cards, autofill, history, bookmarks) from major Chromium-based and Firefox browsers; it bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL using Early Bird APC to call the IElevator COM interface, and uses DPAPI/NSS methods for other browsers. The report describes the tool's components, supported browsers, evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), operational usage examples, detection opportunities (injection, IElevator calls, unusual SQLite reads), and mitigation recommendations (use of external credential managers and EDRs monitoring IElevator/headless browser behavior).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.