logo

SQL Injection Tool for MS-SQL Released for Download

ID: 3f7be3dd-e9b6-55fe-bd15-81351659658e

STIX ID: report--3f7be3dd-e9b6-55fe-bd15-81351659658e

Feed Name: Darknet

Threat Score
75/100

Date Published: 2007-11-19

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly documented post‑exploitation tool that harvests browser‑stored credentials and session tokens across major Chromium‑based browsers and Firefox. It bypasses Chrome's App‑Bound Encryption by injecting a DLL into a spawned headless Chromium process to call the IElevator COM interface (using Early Bird APC injection), retrieves decryption keys (or DPAPI/NSS keys for other browsers), and parses on‑disk browser databases to output structured JSON. The report covers supported browsers and data types, evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), an attack scenario demonstrating rapid credential extraction for lateral movement and cloud account takeover, and detection/mitigation guidance for EDR and policy controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.