logo

PowerShell Runspace Portable Post Exploitation Tool

ID: 3f94eb9e-7768-5160-b9d2-661d9c8e6e67

STIX ID: report--3f94eb9e-7768-5160-b9d2-661d9c8e6e67

Feed Name: Darknet

Threat Score
70/100

Date Published: 2016-08-20

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets Chromium-based and Firefox browsers on Windows, using a compiled executable and a DLL injected into a headless Chromium process to bypass App-Bound Encryption via the IElevator COM interface (and handling DPAPI/NSS where applicable). It extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill and history into JSON, includes multiple operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection, custom SQLite parsing), and is positioned for red-team assumed-breach testing while representing a significant real-world risk if used maliciously.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.