logo

pwdump6 version 1.2 BETA Released

ID: 2cf55801-d5dc-50bd-924f-4ec06fa4c6fb

STIX ID: report--2cf55801-d5dc-50bd-924f-4ec06fa4c6fb

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-03-20

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card numbers, autofill data and browsing history from major Chromium‑based and Firefox browsers on Windows. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface, handles DPAPI and NSS decryption for other browsers, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection), outputs structured JSON, and is positioned for red team use but represents a realistic capability for cloud account takeover and lateral movement if misused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.