logo

Hacking your $60 Router into a $600 Router

ID: 36309b34-ae5c-51ad-86ea-0a5962d37b48

STIX ID: report--36309b34-ae5c-51ad-86ea-0a5962d37b48

Feed Name: Darknet

Threat Score
78/100

Date Published: 2007-01-28

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post-exploitation credential-harvesting tool that targets major Chromium-based and Firefox browsers to extract saved passwords, session cookies, OAuth refresh tokens, credit cards, autofill data and history. It implements an App-Bound Encryption bypass for Chrome/Brave/Edge by spawning a headless Chromium process and injecting a DLL that uses the IElevator COM interface to decrypt the app_bound_encrypted_key, handles DPAPI for Opera/Vivaldi variants and NSS for Firefox, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication) while outputting results as structured JSON; the report also covers usage examples, detection opportunities and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.