logo

NASA Systems At Risk From Hacking Attacks

ID: 32fc7416-05ea-5a29-b395-1d0e1da071a2

STIX ID: report--32fc7416-05ea-5a29-b395-1d0e1da071a2

Feed Name: Darknet

Threat Score
80/100

Date Published: 2011-03-30

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a publicly released post‑exploitation tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major Chromium- and Gecko-based browsers on Windows. It implements an App‑Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and injecting a DLL (Early Bird APC) to use the IElevator COM interface to decrypt keys, uses DPAPI extraction for Opera/Opera GX/Vivaldi, and NSS decryption for Firefox; the tool includes multiple operational evasion features and is intended for red-team/assumed‑breach testing but poses a significant risk if abused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.