logo

FBI Investigating Gawker Media User Database Password Ownage

ID: 34acd078-a8f3-5c34-9ae4-4232a56e7e05

STIX ID: report--34acd078-a8f3-5c34-9ae4-4232a56e7e05

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-12-15

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly documented post‑exploitation credential‑harvesting tool that extracts passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks from Chromium-based browsers (Chrome, Edge, Brave, Opera, Vivaldi) and Firefox. It implements an App‑Bound Encryption bypass for Chrome 127+ by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt the app_bound_encrypted_key, and uses DPAPI/NSS procedures for other browsers; the tool includes operational evasion features, writes structured JSON output, and includes detection and mitigation guidance for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.