logo

PRISM, Edward Snowden, Big Brother & More Stuff We Already Knew

ID: 3593ecfc-9a2a-5a02-8194-680ce8b294f8

STIX ID: report--3593ecfc-9a2a-5a02-8194-680ce8b294f8

Feed Name: Darknet

Threat Score
75/100

Date Published: 2013-06-18

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets major Windows browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox) to extract saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt the app_bound_encrypted_key, uses DPAPI or NSS decryption for other browsers, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, and a custom SQLite parser). The report highlights practical attack scenarios, detection opportunities (unexpected process injection, headless browser instantiation, reads of browser SQLite DBs, IElevator calls), and mitigation strategies such as using external credential managers and EDR rules that monitor for these specific behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.