logo

Veterans Administration Chief Says Laptop Recovered

ID: 3932aaa0-f48e-55f5-9e72-c2c571beb34b

STIX ID: report--3932aaa0-f48e-55f5-9e72-c2c571beb34b

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-07-04

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a publicly available post‑exploitation tool that extracts browser-stored credentials (passwords, cookies, OAuth tokens, credit cards, autofill, history, bookmarks) from Chrome, Edge, Brave, Opera-family browsers and Firefox. It implements an App‑Bound Encryption bypass for Chromium browsers by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface, supports DPAPI and NSS decryption for other browsers, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication, custom SQLite parser), and is positioned as a red‑team utility with clear detection and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.