logo

Open Source Vulnerability Management System

ID: 3669d9f8-0667-51ba-a8ca-00f03b053e87

STIX ID: report--3669d9f8-0667-51ba-a8ca-00f03b053e87

Feed Name: Darknet

Threat Score
75/100

Date Published: 2015-02-24

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a precompiled Windows post‑exploitation tool that harvests browser-stored credentials and session tokens from Chromium-based browsers (Chrome, Edge, Brave, Opera-derived browsers) and Firefox by bypassing App-Bound Encryption, DPAPI, and NSS protections; it injects a DLL into a headless Chromium process (Early Bird APC) to call the IElevator COM interface, retrieves decryption keys, parses on-disk SQLite/JSON stores, and outputs structured JSON. The report details supported browsers and data types, operational evasion (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), a realistic attack scenario, and recommended detection/mitigation approaches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.