logo

Automated Web Auditing and Exploitation Framework

ID: 35f7e0a5-cc0a-5735-b980-d68d9bdd3507

STIX ID: report--35f7e0a5-cc0a-5735-b980-d68d9bdd3507

Feed Name: Darknet

Threat Score
75/100

Date Published: 2008-01-15

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post-exploitation credential-harvesting tool targeting Chrome, Edge, Brave, Opera (including Opera GX), Vivaldi and Firefox; it bypasses App‑Bound Encryption by injecting a DLL into a headless Chromium process to use the IElevator COM interface, retrieves DPAPI and NSS-protected secrets where applicable, and outputs structured JSON. The tool includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), is intended for red-team assumed-breach testing but represents a substantial real-world infostealer risk, and the report includes detection opportunities and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.