logo

Generation-based Context-free Grammar Fuzzing Tool

ID: 37886ddf-de76-570a-99e5-c672a7772e57

STIX ID: report--37886ddf-de76-570a-99e5-c672a7772e57

Feed Name: Darknet

Threat Score
75/100

Date Published: 2015-07-20

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks from major browsers (Chrome/Edge/Brave via App-Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It operates by spawning a headless Chromium process, injecting a DLL using Early Bird APC to use the IElevator COM interface to decrypt app-bound keys, and parsing on-disk browser databases; the tool includes numerous evasion features for use in red-team or malicious post-exploitation scenarios and outputs structured JSON for recovered artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.