logo

Caracal – Rust eBPF Rootkit for Stealthy Post-Exploitation

ID: 3245fc92-6f34-583c-a1f0-05ea23ff5113

STIX ID: report--3245fc92-6f34-583c-a1f0-05ea23ff5113

Feed Name: Darknet

Threat Score
75/100

Date Published: 2025-07-07

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a precompiled Windows post-exploitation tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox by bypassing App-Bound Encryption (using a headless Chromium process, Early Bird APC DLL injection and the IElevator COM interface) or by DPAPI/NSS decryption; the report documents its internals, operational evasion techniques, example attack scenarios, detection opportunities, and relevance to red teams and enterprise defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.