logo

Sniff Passwords From Interface or PCAP File

ID: 3707f372-6135-5e1a-96f0-f1e610f50e5c

STIX ID: report--3707f372-6135-5e1a-96f0-f1e610f50e5c

Feed Name: Darknet

Threat Score
72/100

Date Published: 2017-12-14

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly documented post‑exploitation tool that harvests browser-stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill data, history and bookmarks) from major Chromium-based and Firefox browsers. It implements an App‑Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface, retrieves DPAPI and NSS secrets where applicable, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, and a custom SQLite parser). The report covers usage, attack scenarios, detection opportunities (unexpected process injection, headless browser instantiation, reads of Login Data/Cookies/Web Data by non-browser processes, IElevator COM calls), and mitigation recommendations such as moving secrets out of browsers and monitoring the IElevator interface.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.