logo

Static Code Analysis Security Scanner For Ruby

ID: 353bf39e-69ef-50dc-b175-618e9265e36c

STIX ID: report--353bf39e-69ef-50dc-b175-618e9265e36c

Feed Name: Darknet

Threat Score
75/100

Date Published: 2014-06-23

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly documented post‑exploitation tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major Windows browsers (Chrome/Edge/Brave via an App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It uses a headless Chromium process with Early Bird APC DLL injection to leverage the IElevator COM interface to decrypt app_bound_encrypted_key, includes multiple EDR‑evasion features, outputs structured JSON for red team usage, and is positioned as a way to assess the real impact of compromised developer workstations on SaaS/cloud account takeover.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.