logo

Want Some COFEE? Microsoft Computer Online Forensic Evidence Extractor

ID: 3eb8df57-29e3-5406-adbd-6514d789b636

STIX ID: report--3eb8df57-29e3-5406-adbd-6514d789b636

Feed Name: Darknet

Threat Score
75/100

Date Published: 2008-05-09

Date Updated: 2026-05-14

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill and history) from major Chromium-based browsers and Firefox on Windows by bypassing App-Bound Encryption and DPAPI. The tool uses a headless Chromium process with Early Bird APC DLL injection to leverage the IElevator COM interface for key decryption, includes multiple operational evasion techniques, outputs structured JSON for red team use, and poses a high-risk credential-exposure vector for compromised developer or user endpoints; the report also outlines detection opportunities and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.