logo

Merry Xmas From Darknet

ID: 2ec634da-407f-5d50-8f87-f578faf8b215

STIX ID: report--2ec634da-407f-5d50-8f87-f578faf8b215

Feed Name: Darknet

Threat Score
75/100

Date Published: 2007-12-24

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a post-exploitation credential-extraction tool that targets Chrome, Edge, Brave (App-Bound Encryption bypass via IElevator), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS) to harvest saved passwords, session cookies, OAuth tokens, credit cards, autofill data and history. It uses a compiled executable plus a DLL injected into a headless Chromium process (Early Bird APC) to decrypt app_bound_encrypted_key, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON, and is presented as a red-team tool useful for assessing realistic credential exposure and testing EDR controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.